CVE-2006-1944
SibSoft CommuniMail < 1.2 - Cross-Site Scripting via list_id and form_id Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-1944. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in CommuniMail, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'form_id' parameter.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in CommuniMail, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'form_id' parameter.
The provided text describes a cross-site scripting (XSS) vulnerability in CommuniMail, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject malicious script code via the 'list_id' parameter.