CVE-2006-6364
Inside Systems Mail <= 2.0 - Cross-Site Scripting via Error Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6364. PoCs published by Vicente Aguilera Diaz.
AI-analyzed exploit summary The exploit describes a cross-site scripting (XSS) vulnerability in Inside Systems Mail version 2.0. The vulnerability arises due to insufficient input sanitization in the 'error' parameter of the error.php file, allowing arbitrary script execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in error.php in Inside Systems Mail (ISMail) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
Exploits (1)
The exploit describes a cross-site scripting (XSS) vulnerability in Inside Systems Mail version 2.0. The vulnerability arises due to insufficient input sanitization in the 'error' parameter of the error.php file, allowing arbitrary script execution in the context of the affected site.