CVE-2006-1120

DCP-Portal <= 6.1.1 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2006-1120. PoCs published by Nenad Jovanovic.

AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in DCP Portal by injecting malicious scripts into various parameters of the 'mycontents.php' file. The scripts redirect the user's cookies to an attacker-controlled server.

Description

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4) images parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7) subject, (8) body, and (9) mid parameters to (c) forums.php; (10) subject and (11) message parameters to (d) inbox.php; (12) subject_color and (13) email parameters to (e) lostpassword.php; and the (14) c_name, (15) content_inicial, and (16) cid parameters to (f) mycontents.php. NOTE: the calendar.php/day vector is already subsumed by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and search.php/q parameters for calendar.php are already subsumed by CVE-2004-2511.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Nenad Jovanovic · textwebappsphp
https://www.exploit-db.com/exploits/27395

This exploit demonstrates multiple XSS vulnerabilities in DCP Portal by injecting malicious scripts into various parameters of the 'mycontents.php' file. The scripts redirect the user's cookies to an attacker-controlled server.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DCP Portal 6.1.1
No auth needed
Prerequisites: Access to the vulnerable DCP Portal instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Nenad Jovanovic · textwebappsphp
https://www.exploit-db.com/exploits/27394

This exploit demonstrates multiple XSS vulnerabilities in DCP Portal by injecting malicious scripts via the 'subject_color' and 'email' parameters in the lostpassword.php page. The scripts redirect users to a malicious site to steal cookies.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DCP Portal 6.1.1
No auth needed
Prerequisites: Access to the vulnerable DCP Portal instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Nenad Jovanovic · textwebappsphp
https://www.exploit-db.com/exploits/27390

This exploit demonstrates multiple XSS vulnerabilities in DCP Portal by injecting malicious JavaScript via the 'its_url' and 'url' parameters. The PoC redirects the victim's browser to a malicious site while exfiltrating cookie data.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DCP Portal 6.1.1
No auth needed
Prerequisites: Victim must visit a crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Nenad Jovanovic · textwebappsphp
https://www.exploit-db.com/exploits/27393

This exploit demonstrates multiple XSS vulnerabilities in DCP Portal by injecting malicious JavaScript into form inputs, which can steal cookies when executed in a victim's browser.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DCP Portal 6.1.1
No auth needed
Prerequisites: Victim interaction required to trigger the XSS payload
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Nenad Jovanovic · textwebappsphp
https://www.exploit-db.com/exploits/27392

This exploit demonstrates multiple XSS vulnerabilities in DCP Portal by injecting malicious scripts into various input fields, leading to cookie theft. The PoC includes both GET and POST-based attack vectors.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DCP Portal 6.1.1
No auth needed
Prerequisites: Access to the target application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Nenad Jovanovic · textwebappsphp
https://www.exploit-db.com/exploits/27391

This exploit demonstrates multiple XSS vulnerabilities in DCP Portal's calendar.php by injecting malicious scripts via unsanitized parameters like subject_color, images, day, and year. The scripts redirect users to a malicious site to steal cookies.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DCP Portal 6.1.1
No auth needed
Prerequisites: Access to the vulnerable DCP Portal instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25279
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23979
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23981
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/427175/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23980
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17050
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/392
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23978
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23976
Exploit, Vendor Advisory x_refsource_misc
http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-001.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23977

Scores

EPSS 0.0293
EPSS Percentile 85.3%

Details

Status published
Products (13)
codeworx_technologies/dcp-portal 3.7
codeworx_technologies/dcp-portal 4.0
codeworx_technologies/dcp-portal 4.1
codeworx_technologies/dcp-portal 4.2
codeworx_technologies/dcp-portal 4.5.1
codeworx_technologies/dcp-portal 5.0.1
codeworx_technologies/dcp-portal 5.0.2
codeworx_technologies/dcp-portal 5.1
codeworx_technologies/dcp-portal 5.2
codeworx_technologies/dcp-portal 5.3
... and 3 more
Published Mar 09, 2006
Tracked Since Feb 18, 2026