CVE-2005-4205
locazolist_classifieds < 1.03c - Cross-Site Scripting via searchdb.asp q Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4205. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary The provided text describes a vulnerability in LocazoList Classifieds that allows for cross-site scripting (XSS) and SQL injection (SQLi) attacks due to insufficient input validation. The vulnerability can be exploited via the 'q' parameter in the searchdb.asp page.
Description
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
Exploits (1)
The provided text describes a vulnerability in LocazoList Classifieds that allows for cross-site scripting (XSS) and SQL injection (SQLi) attacks due to insufficient input validation. The vulnerability can be exploited via the 'q' parameter in the searchdb.asp page.