CVE-2006-6523
cPanel 11 - Cross-Site Scripting via BoxTrapper Account Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6523. PoCs published by Aria-Security Team.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in cPanel BoxTrapper, where user-supplied input is not properly sanitized. The vulnerability allows arbitrary script execution in a user's browser, potentially leading to credential theft.
Description
Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in cPanel BoxTrapper, where user-supplied input is not properly sanitized. The vulnerability allows arbitrary script execution in a user's browser, potentially leading to credential theft.