CVE-2006-1679
Jupiter CMS 1.1.5 - Cross-Site Scripting via Layout Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1679. PoCs published by KaDaL-X.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Jupiter CMS by injecting arbitrary HTML/JavaScript via the 'layout' parameter. The PoC uses a simple marquee tag to prove the lack of input sanitization.
Description
Cross-site scripting (XSS) vulnerability in modules/online.php in Jupiter CMS 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the layout parameter to index.php.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Jupiter CMS by injecting arbitrary HTML/JavaScript via the 'layout' parameter. The PoC uses a simple marquee tag to prove the lack of input sanitization.