CVE-2006-2803
PHP ManualMaker 1.0 - Cross-Site Scripting via id Parameter or Search/Comment Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2803. PoCs published by Luny.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in PHP ManualMaker due to improper input sanitization. It includes a proof-of-concept URL demonstrating how an attacker could inject arbitrary HTML or script code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in PHP ManualMaker due to improper input sanitization. It includes a proof-of-concept URL demonstrating how an attacker could inject arbitrary HTML or script code.