CVE-2006-5512
Zwahlen Online Shop - Cross-Site Scripting via article.htm cat Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-5512. PoCs published by MC.Iglo, Crackers_Child.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in Zwahlen's Online Shop by injecting a script tag into the 'cat' parameter of the 'article.htm' URL. The lack of input sanitization allows arbitrary JavaScript execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
Exploits (2)
The exploit demonstrates a reflected XSS vulnerability in Zwahlen's Online Shop by injecting a script tag into the 'cat' parameter of the 'article.htm' URL. The lack of input sanitization allows arbitrary JavaScript execution in the context of the affected site.
The exploit demonstrates a directory traversal vulnerability in INCA IM-204 devices, allowing unauthenticated attackers to access sensitive files like /etc/passwd, /etc/shadow, and configuration files via malformed input in the 'getpage' parameter.