Record summary

CVE-2006-2491 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBBoastMachine 3.1 - 'admin.php' Cross-Site ScriptingExploitDB exploitby Yunus Emre YilmazNot analyzed1 file
ExploitDB

PoC details

References

10