CVE-2006-3052
Event Registration - Cross-Site Scripting via Event ID or Select Events Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3052. PoCs published by Luny.
AI-analyzed exploit summary This exploit demonstrates multiple reflected XSS vulnerabilities in various CEScripts applications due to insufficient input sanitization. The PoC provides URLs with injected script tags that execute arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Exploits (1)
This exploit demonstrates multiple reflected XSS vulnerabilities in various CEScripts applications due to insufficient input sanitization. The PoC provides URLs with injected script tags that execute arbitrary JavaScript in the context of the affected site.