CVE-2006-0251
faq-o-matic < 2.711 - Cross-Site Scripting via _duration, file, or cmd Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0251. PoCs published by Preddy.
AI-analyzed exploit summary The provided text describes multiple XSS vulnerabilities in Faq-O-Matic due to improper input sanitization. It includes example URLs demonstrating how arbitrary script code can be executed in a user's browser context.
Description
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.
Exploits (1)
The provided text describes multiple XSS vulnerabilities in Faq-O-Matic due to improper input sanitization. It includes example URLs demonstrating how arbitrary script code can be executed in a user's browser context.