CVE-2006-4742
IDevSpot PhpLinkExchange 1.0 - Cross-Site Scripting via User Add Msg Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4742. PoCs published by s3rv3r_hack3r.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in PhpLinkExchange by idevspot.com, allowing an attacker to include arbitrary files via the 'svr_rootPhpStart' parameter. Additionally, it highlights an XSS vulnerability in the 'msg' parameter of user_add.php.
Description
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in PhpLinkExchange by idevspot.com, allowing an attacker to include arbitrary files via the 'svr_rootPhpStart' parameter. Additionally, it highlights an XSS vulnerability in the 'msg' parameter of user_add.php.