CVE-2006-5975
BlogMe 3.0 - Stored Cross-Site Scripting via Name URL or Comments Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5975. PoCs published by Security Access Point.
AI-analyzed exploit summary This is a writeup describing an SQL injection-based authentication bypass and XSS vulnerability in BlogMe v3. It provides payloads for bypassing admin login and identifies vulnerable fields for XSS in the comments section.
Description
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.
Exploits (1)
This is a writeup describing an SQL injection-based authentication bypass and XSS vulnerability in BlogMe v3. It provides payloads for bypassing admin login and identifies vulnerable fields for XSS in the comments section.