CVE-2006-4295
Panda ActiveScan 5.53.00 - Cross-Site Scripting via ascan_6.asp Email Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4295. PoCs published by Lostmon.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Panda ActiveScan 5.53.00 by injecting arbitrary script code via the 'email' parameter in a URL. The vulnerability arises due to insufficient input sanitization, allowing execution of malicious scripts in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Panda ActiveScan 5.53.00 by injecting arbitrary script code via the 'email' parameter in a URL. The vulnerability arises due to insufficient input sanitization, allowing execution of malicious scripts in the context of the affected site.