CVE-2006-1486
realestateZONE < 4.2 - Cross-Site Scripting via bamin, bemin, pmin, or state Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1486. PoCs published by r0t.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in realestateZONE by injecting script tags into URL parameters. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in realestateZONE by injecting script tags into URL parameters. The PoC shows how arbitrary JavaScript can be executed in the context of the affected site.