CVE-2005-4239
PHP JackKnife < 2.21 - Cross-Site Scripting via sKeywords Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4239. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP JackKnife due to insufficient input sanitization. The PoC provides a URL with a malicious script tag that executes arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in Search/DisplayResults.php in PHP JackKnife 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via URL-encoded values in the sKeywords parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP JackKnife due to insufficient input sanitization. The PoC provides a URL with a malicious script tag that executes arbitrary JavaScript in the context of the affected site.