Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-0358. PoCs published by night_warrior771.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in PowerPortal, where user-supplied input is not properly sanitized. It includes example URLs demonstrating how an attacker could inject arbitrary script code.
Description
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in PowerPortal, where user-supplied input is not properly sanitized. It includes example URLs demonstrating how an attacker could inject arbitrary script code.
The provided text describes a cross-site scripting (XSS) vulnerability in PowerPortal, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code into the 'search' parameter.