CVE-2006-2249
CuteNews < 1.4.1 - Cross-Site Scripting via Search Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2249. PoCs published by NST.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in CuteNews by injecting malicious JavaScript via unsanitized input parameters in the search.php endpoint. The PoC includes URLs with script tags that trigger alerts or redirects, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in CuteNews by injecting malicious JavaScript via unsanitized input parameters in the search.php endpoint. The PoC includes URLs with script tags that trigger alerts or redirects, confirming the vulnerability.