CVE-2005-4262
Envolution - Cross-Site Scripting via News Module Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4262. PoCs published by X1ngBox.
AI-analyzed exploit summary The provided text describes XSS vulnerabilities in Envolution CMS via the 'catid' and 'startrow' parameters in the News module. No actual exploit code is present, only URLs demonstrating the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).
Exploits (1)
The provided text describes XSS vulnerabilities in Envolution CMS via the 'catid' and 'startrow' parameters in the News module. No actual exploit code is present, only URLs demonstrating the vulnerability.