CVE-2005-4698
TellMe <= 1.2 - Cross-Site Scripting via q_IP or q_Host Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4698. PoCs published by Donnie Werner.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in TellMe by injecting an iframe via the 'q_Host' parameter. The lack of input sanitization allows arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the 91) q_IP (IP) or (2) q_Host (HOST) parameters.
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in TellMe by injecting an iframe via the 'q_Host' parameter. The lack of input sanitization allows arbitrary script execution in the context of the affected site.