CVE-2006-1233
WMNews - Cross-Site Scripting via ArtCat, ctrrowcol, or ArtID Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-1233. PoCs published by R00T3RR0R.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in WMNews due to improper input sanitization. The PoC shows how arbitrary script code can be executed in the context of the affected site via a crafted URL.
Description
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.
Exploits (3)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WMNews due to improper input sanitization. The PoC shows how arbitrary script code can be executed in the context of the affected site via a crafted URL.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WMNews due to improper input sanitization. The PoC URL injects arbitrary JavaScript code via the 'ArtID' parameter, which executes in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WMNews due to improper input sanitization. The PoC shows how arbitrary script code can be executed in the context of the affected site via a crafted URL.