CVE-2006-6380
Ultimate HelpDesk - Cross-Site Scripting via Index.asp Keyword Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6380. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Ultimate HelpDesk: a directory traversal flaw allowing arbitrary file access via `getfile.asp` and a reflected XSS vulnerability in `index.asp`. Both require user interaction or authentication.
Description
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
Exploits (1)
This exploit demonstrates two vulnerabilities in Ultimate HelpDesk: a directory traversal flaw allowing arbitrary file access via `getfile.asp` and a reflected XSS vulnerability in `index.asp`. Both require user interaction or authentication.