CVE-2006-3186
CMS Faethon 1.3.2 - Cross-Site Scripting via mainpath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3186. PoCs published by K-159.
AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in CMS Faethon 1.3.2 due to unsanitized input in the $mainpath variable. The advisory includes a proof-of-concept URL but no actual exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpath parameter to (1) data/footer.php and (2) admin/header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Exploits (1)
This is a writeup describing a remote file inclusion vulnerability in CMS Faethon 1.3.2 due to unsanitized input in the $mainpath variable. The advisory includes a proof-of-concept URL but no actual exploit code.