CVE-2005-4298
AtlantForum < 4.02 - Cross-Site Scripting via sch_allsubct, before, or ct Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4298. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in AtlantForum by injecting arbitrary JavaScript via unsanitized input parameters in the URL. The PoC includes crafted URLs that trigger script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in AtlantForum by injecting arbitrary JavaScript via unsanitized input parameters in the URL. The PoC includes crafted URLs that trigger script execution in the context of the affected site.