CVE-2006-2425
phpremoteview < 2003-10-23 - Cross-Site Scripting via f, d, ref Parameters and MAKE DIR, Full file name Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2425. PoCs published by Soot.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in PhpRemoteView due to improper input sanitization. It provides proof-of-concept URLs that inject arbitrary JavaScript code into the application's parameters.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields.
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in PhpRemoteView due to improper input sanitization. It provides proof-of-concept URLs that inject arbitrary JavaScript code into the application's parameters.