Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-3359. PoCs published by securityconnection.
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in NewsPHP 2006 PRO due to improper input sanitization. It includes a sample exploit URL for SQL injection but lacks executable code.
Description
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in (b) inc/rss_feed.php.
Exploits (1)
The provided text describes SQL injection and XSS vulnerabilities in NewsPHP 2006 PRO due to improper input sanitization. It includes a sample exploit URL for SQL injection but lacks executable code.