CVE-2006-3143
Maximus SchoolMAX iCue and iParent - Cross-Site Scripting via icue_login.asp error_msg Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3143. PoCs published by Charles Hooper.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Maximus SchoolMAX, where user-supplied input is not sanitized before being displayed. An example URL is given to demonstrate the vulnerability, but no actual exploit code is present.
Description
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Maximus SchoolMAX, where user-supplied input is not sanitized before being displayed. An example URL is given to demonstrate the vulnerability, but no actual exploit code is present.