CVE-2006-1110
Aztek Forum 4.0 - Stored Cross-Site Scripting via Message Body
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1110. PoCs published by lorenzo.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in AZTEK forums 4.0, including XSS via crafted input in the 'Citer' function, SQL injection via a malformed 'msg' parameter, and a MySQL error-based information leak through unvalidated user registration. The PoC includes specific payloads and steps to trigger these issues.
Description
Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in AZTEK forums 4.0, including XSS via crafted input in the 'Citer' function, SQL injection via a malformed 'msg' parameter, and a MySQL error-based information leak through unvalidated user registration. The PoC includes specific payloads and steps to trigger these issues.