CVE-2006-6082
CreaScripts Creadirectory - Cross-Site Scripting via cat Parameter or search Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-6082. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes a vulnerability in Creascripts creadirectory version 1.2, highlighting SQL injection and XSS issues due to insufficient input sanitization. It includes a generic XSS example URL but lacks actual exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
Exploits (2)
The provided text describes a vulnerability in Creascripts creadirectory version 1.2, highlighting SQL injection and XSS issues due to insufficient input sanitization. It includes a generic XSS example URL but lacks actual exploit code.
The provided text describes a vulnerability in Creascripts creadirectory version 1.2, highlighting SQL injection and XSS issues due to insufficient input sanitization. It includes a basic example of an XSS payload but lacks executable exploit code.