Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-1504. PoCs published by o.y.6.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ArabPortal System 2.0 due to improper input sanitization. The PoC shows how arbitrary script code can be executed in the context of the affected site via the 'title' parameter in the 'online.php' URL.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ArabPortal System 2.0 due to improper input sanitization. The PoC shows how arbitrary script code can be executed in the context of the affected site via the 'title' parameter in the 'online.php' URL.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ArabPortal System 2.0 due to improper input sanitization in the 'title' parameter of the download.php script. An attacker can inject arbitrary JavaScript code to execute in the context of a victim's browser session.