CVE-2006-5915
SAMEDIA LandShop - Cross-Site Scripting via ls.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5915. PoCs published by laurent gaffie.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in LandShop by injecting malicious JavaScript via unsanitized input parameters. The PoC URLs trigger alert popups displaying the user's cookies, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in LandShop by injecting malicious JavaScript via unsanitized input parameters. The PoC URLs trigger alert popups displaying the user's cookies, confirming the vulnerability.