CVE-2006-1349
Musicbox 2.3 Beta 2 - Cross-Site Scripting via id, type, show, and message1 Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-1349. PoCs published by Linux_Drox.
AI-analyzed exploit summary The exploit demonstrates XSS vulnerabilities in MusicBox by injecting JavaScript via unsanitized input parameters. It includes multiple attack vectors targeting different URL parameters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) type and (3) show parameters in a top action in (a) index.php; and the (4) message1 parameter in (b) cart.php.
Exploits (2)
The exploit demonstrates XSS vulnerabilities in MusicBox by injecting JavaScript via unsanitized input parameters. It includes multiple attack vectors targeting different URL parameters.
The provided text describes XSS and SQL injection vulnerabilities in MusicBox, with example URLs demonstrating XSS payloads. No executable exploit code is present.