CVE-2006-1157
ADP Forum 2.0.3 - Stored Cross-Site Scripting via Subject Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1157. PoCs published by liz0.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in ADP Forum 2.0.3 and prior. The provided payload redirects users to a malicious site via a script tag, leveraging improper input sanitization.
Description
Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Subject field (possibly messaggio parameter) when posting a new message in post.php.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in ADP Forum 2.0.3 and prior. The provided payload redirects users to a malicious site via a script tag, leveraging improper input sanitization.