CVE-2009-3225
published 2009-09-16CVE-2009-3225: Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
1.51%
71.3th percentile
Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some of these details are obtained from third party information.
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
AlmondSoft Multiple Classifieds Products - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
exploitdb·2009-06-27
CVE-2009-3225 AlmondSoft Multiple Classifieds Products - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
AlmondSoft Multiple Classifieds Products - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
---
source: https://www.securityfocus.com/bid/35816/info
AlmondSoft Almond Classifieds is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AlmondSoft Almond Classifieds Enterprise, Pro, and WAP Editions are vulnerable.
http://www.example.com/wap/index.php?md=browse&ct=manw&city=Akron%20OH&page=1alert(317158806252)
http://www.example.com/clnt/index.php?ct=evntcl&md=browse&mds=s
Exploit-DB
AlmondSoft Classifieds Pro - 'gmap.php?addr' Cross-Site Scripting
exploitdb·2009-06-27
CVE-2009-3225 AlmondSoft Classifieds Pro - 'gmap.php?addr' Cross-Site Scripting
AlmondSoft Classifieds Pro - 'gmap.php?addr' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/35816/info
AlmondSoft Almond Classifieds is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AlmondSoft Almond Classifieds Enterprise, Pro, and WAP Editions are vulnerable.
http://www.example.com/pro/gmap.php?addr=">alert(document.cookie);
2009-09-16
Published