CVE-2006-0409
Pixelpost Photoblog 1.4.3 - Stored Cross-Site Scripting via Add Comment Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0409. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary The provided text describes an HTML injection vulnerability in Pixelpost, where user-supplied input is not properly sanitized, leading to potential XSS attacks. The example exploit demonstrates how an attacker could inject malicious HTML or script code via the 'Add Comment' field.
Description
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.
Exploits (1)
The provided text describes an HTML injection vulnerability in Pixelpost, where user-supplied input is not properly sanitized, leading to potential XSS attacks. The example exploit demonstrates how an attacker could inject malicious HTML or script code via the 'Add Comment' field.