CVE-2006-4479
Visual Shapers ezContents 2.0.3 - Cross-Site Scripting via subgroupname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4479. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ezContents by injecting a script tag via the 'subgroupname' parameter in loginreq2.php. The PoC uses a simple alert to confirm the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ezContents by injecting a script tag via the 'subgroupname' parameter in loginreq2.php. The PoC uses a simple alert to confirm the vulnerability.