CVE-2006-0857
e107 Chatbox Plugin 1.0 - Stored Cross-Site Scripting via Chatbox Input
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0857. PoCs published by marc & shb.
AI-analyzed exploit summary This exploit demonstrates an HTML-injection vulnerability in the e107 CMS Chatbox Plugin. The PoC provides a simple script tag that, when injected into the chatbox, executes arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.
Exploits (1)
This exploit demonstrates an HTML-injection vulnerability in the e107 CMS Chatbox Plugin. The PoC provides a simple script tag that, when injected into the chatbox, executes arbitrary JavaScript in the context of the affected site.