CVE-2006-0880
Noah's Classifieds 1.3 - Cross-Site Scripting via inf, upperTemplate, or lowerTemplate Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0880. PoCs published by trueend5.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Noah's Classifieds by injecting arbitrary script code via the 'inf' and 'upperTemplate' parameters. The PoC uses basic JavaScript alerts to prove the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in Noah's Classifieds by injecting arbitrary script code via the 'inf' and 'upperTemplate' parameters. The PoC uses basic JavaScript alerts to prove the vulnerability.