CVE-2006-2680
AZ Photo Album Script Pro - Cross-Site Scripting via gazpart Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2680. PoCs published by Luny.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in AZ Photo Album Script Pro by injecting malicious script tags into the 'gazpart' parameter of the index.php URL. The PoC triggers an alert dialog, proving arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in AZ Photo Album Script Pro by injecting malicious script tags into the 'gazpart' parameter of the index.php URL. The PoC triggers an alert dialog, proving arbitrary script execution in the context of the affected site.