CVE-2005-1075
RadScripts RadBids Gold 2 - Cross-Site Scripting via FAQ or Index Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-1075. PoCs published by Dcrab.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in RadBids Gold v2, including arbitrary file disclosure, SQL injection, and cross-site scripting (XSS). It includes example URLs demonstrating XSS exploitation but does not contain executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.
Exploits (2)
The provided text describes multiple vulnerabilities in RadBids Gold v2, including arbitrary file disclosure, SQL injection, and cross-site scripting (XSS). It includes example URLs demonstrating XSS exploitation but does not contain executable exploit code.
The provided text describes multiple vulnerabilities in RadBids Gold v2, including arbitrary file disclosure, SQL injection, and cross-site scripting (XSS). It includes an example XSS payload but lacks executable exploit code.