CVE-2006-6520
Messageriescripthp 2.0 - Cross-Site Scripting via Pseudo, Email, PageName, or CSSForm Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-6520. PoCs published by Mr_KaLiMaN.
AI-analyzed exploit summary The provided text describes a vulnerability in Messageriescripthp V2.0, specifically XSS and SQL injection issues due to insufficient input validation. It includes a sample URL demonstrating the XSS vulnerability but lacks actual exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php.
Exploits (3)
The provided text describes a vulnerability in Messageriescripthp V2.0, specifically XSS and SQL injection issues due to insufficient input validation. It includes a sample URL demonstrating the XSS vulnerability but lacks actual exploit code.
The provided text describes a vulnerability in Messageriescripthp V2.0, specifically XSS and SQL injection due to insufficient input validation. It includes a sample URL for XSS exploitation but lacks actual exploit code.
The provided text describes XSS and SQL injection vulnerabilities in Messageriescripthp V2.0 but does not include functional exploit code. It outlines attack vectors via unsanitized input in the 'pageName' and 'cssform' parameters.