CVE-2006-3624

FLV Players 8 - Cross-Site Scripting via URL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-3624. PoCs published by xzerox.

AI-analyzed exploit summary The exploit describes multiple cross-site scripting (XSS) vulnerabilities in FLV Player version 8 due to improper input sanitization. It provides example URLs demonstrating how arbitrary script code can be executed in the context of the affected site.

Description

Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by xzerox · textremotemultiple
https://www.exploit-db.com/exploits/28210

The exploit describes multiple cross-site scripting (XSS) vulnerabilities in FLV Player version 8 due to improper input sanitization. It provides example URLs demonstrating how arbitrary script code can be executed in the context of the affected site.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: FLV Player version 8
No auth needed
Prerequisites: Access to the vulnerable FLV Player application
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by xzerox · textremotemultiple
https://www.exploit-db.com/exploits/28209

The provided text describes a cross-site scripting (XSS) vulnerability in FLV Player version 8, where user-supplied input via the 'url' parameter in 'player.php' is not properly sanitized. This allows arbitrary script execution in the context of the affected site.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: FLV Player version 8
No auth needed
Prerequisites: Access to a vulnerable FLV Player instance · Ability to craft a malicious URL with XSS payload
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27727
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439886/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18954

Scores

EPSS 0.0169
EPSS Percentile 74.7%

Details

Status published
Products (1)
flv/flv_player 8
Published Jul 18, 2006
Tracked Since Feb 18, 2026