CVE-2006-1801
planetSearch+ < 2005-10-26 - Cross-Site Scripting via search_exp Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1801. PoCs published by d4igoro.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in PlanetSearch +, where user-supplied input is not properly sanitized. An attacker can exploit this by crafting a malicious URL with script code in the 'search_exp' parameter.
Description
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in PlanetSearch +, where user-supplied input is not properly sanitized. An attacker can exploit this by crafting a malicious URL with script code in the 'search_exp' parameter.