CVE-2006-0534
CyberShop Ultimate E-commerce - Cross-Site Scripting via ortak or kat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0534. PoCs published by B3g0k.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in CyberShop Ultimate E-commerce by injecting malicious scripts via URL parameters. The PoC includes examples of script injection in different parameters to execute arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in CyberShop Ultimate E-commerce by injecting malicious scripts via URL parameters. The PoC includes examples of script injection in different parameters to execute arbitrary JavaScript in the context of the affected site.