CVE-2005-3556
phplist < 2.10.1 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-3556. PoCs published by Tobias Klein.
AI-analyzed exploit summary The provided code is a writeup describing multiple input validation vulnerabilities in PHPList, including XSS, HTTP injection, SQL injection, and directory traversal. It includes a sample XSS payload but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c) admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) action parameter in (h) admin/fckphplist.php.
Exploits (3)
The provided code is a writeup describing multiple input validation vulnerabilities in PHPList, including XSS, HTTP injection, SQL injection, and directory traversal. It includes a sample XSS payload but lacks executable exploit code.
The exploit demonstrates multiple input validation vulnerabilities in PHPList, including XSS, HTTP injection, SQL injection, and directory traversal. It provides specific URLs with malicious payloads to trigger these vulnerabilities.
The provided code is a writeup describing multiple input validation vulnerabilities in PHPList, including XSS, HTTP injection, SQL injection, and directory traversal. It includes a sample XSS payload but lacks executable exploit code.