CVE-2005-3908
Amazon Shop < 5.0.0 - Cross-Site Scripting via Search Query Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3908. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in GhostScripter Amazon Shop 5.0.0 and prior versions, but the included URL demonstrates an XSS payload instead. No functional exploit code is present.
Description
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in GhostScripter Amazon Shop 5.0.0 and prior versions, but the included URL demonstrates an XSS payload instead. No functional exploit code is present.