CVE-2006-5090
Phoenix Evolution CMS - Cross-Site Scripting via mod, action, or pageid Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-5090. PoCs published by Root3r_H3ll.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Phoenix Evolution CMS due to insufficient input sanitization. It includes example URLs demonstrating the vulnerability but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in Phoenix Evolution CMS due to insufficient input sanitization. It includes example URLs demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in Phoenix Evolution CMS due to unsanitized user input. It includes an example URL demonstrating the vulnerability but lacks executable exploit code.