CVE-2006-5810

XOOPS 1.0 - Cross-Site Scripting via newdownloadshowdays Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5810. PoCs published by CvIr.System.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Xoops version 1.0, where user-supplied input is not properly sanitized. The vulnerability can be exploited via a crafted URL parameter, allowing arbitrary script execution in the context of the affected site.

Description

Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTML via the newdownloadshowdays parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by CvIr.System · textwebappsphp
https://www.exploit-db.com/exploits/28914

The provided text describes a cross-site scripting (XSS) vulnerability in Xoops version 1.0, where user-supplied input is not properly sanitized. The vulnerability can be exploited via a crafted URL parameter, allowing arbitrary script execution in the context of the affected site.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Xoops 1.0
No auth needed
Prerequisites: Access to the target URL with the vulnerable parameter
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

EPSS 0.0156
EPSS Percentile 72.7%

Details

Status published
Products (1)
xoops/xoops 1.0
Published Nov 08, 2006
Tracked Since Feb 18, 2026