CVE-2005-3577
Walla TeleSite < 3.0 - Cross-Site Scripting via ts.exe sug Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3577. PoCs published by Rafi Nahum.
AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in Walla TeleSite, including XSS, SQL injection, and path disclosure. It includes a sample XSS payload but lacks executable exploit code.
Description
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Rafi Nahum · textwebappscgi
https://www.exploit-db.com/exploits/26507
The provided text describes multiple input validation vulnerabilities in Walla TeleSite, including XSS, SQL injection, and path disclosure. It includes a sample XSS payload but lacks executable exploit code.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target:
Walla TeleSite version 3.0 and earlier
No auth needed
Prerequisites:
Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/416581/30/0/threaded
Exploit vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1015204
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/15419
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17547
Scores
EPSS
0.0174
EPSS Percentile
74.8%
Details
Status
published
Products (1)
walla_telesite/walla_telesite
< 3.0
Published
Nov 16, 2005
Tracked Since
Feb 18, 2026