CVE-2006-3405
QTOFileManager 1.0 - Cross-Site Scripting via delete, pathext, or edit Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3405. PoCs published by EllipSiS Security.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in QTO File Manager by injecting arbitrary script code via unsanitized input parameters. It includes both GET and POST request examples to trigger the vulnerabilities.
Description
Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in QTO File Manager by injecting arbitrary script code via unsanitized input parameters. It includes both GET and POST request examples to trigger the vulnerabilities.