CVE-2005-4374
allinta < 2.3.2 - Cross-Site Scripting via FAQ or Search Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-4374. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Allinta CMS versions 2.3.2 and earlier. It explains the issue and provides a proof-of-concept URL demonstrating the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to faq.asp and (2) searchQuery parameter to search.asp.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in Allinta CMS versions 2.3.2 and earlier. It explains the issue and provides a proof-of-concept URL demonstrating the vulnerability.
The provided text describes a cross-site scripting (XSS) vulnerability in Allinta CMS versions 2.3.2 and earlier. The vulnerability arises from insufficient input sanitization, allowing arbitrary script execution in a user's browser context.