CVE-2006-5958
infinicart - Cross-Site Scripting via Login Username/Password, Search, and Email Fields
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-5958. PoCs published by laurent gaffie.
AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in Infinicart's demo version by injecting a script tag into the email parameter of sendpassword.asp, which executes arbitrary JavaScript to steal cookies.
Description
Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c) sendpassword.asp.
Exploits (3)
This exploit demonstrates an XSS vulnerability in Infinicart's demo version by injecting a script tag into the email parameter of sendpassword.asp, which executes arbitrary JavaScript to steal cookies.
This exploit demonstrates an XSS vulnerability in Infinicart's search functionality by injecting a script tag that triggers an alert with the document cookie. It targets the demonstration version of Infinicart.
The provided text describes XSS and SQL injection vulnerabilities in Infinicart's demo login page. It includes example payloads for XSS but lacks executable exploit code.