CVE-2006-6536

Cilem Haber Free Edition - Cross-Site Scripting via hata Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6536. PoCs published by ShaFuck31.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Ã?ilem Haber Free Edition, where user-supplied input is not properly sanitized in the 'hata' parameter of 'hata.asp'. An attacker can exploit this to execute arbitrary script code in a user's browser.

Description

Cross-site scripting (XSS) vulnerability in hata.asp in Cilem Haber Free Edition allows remote attackers to inject arbitrary web script or HTML via the hata parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ShaFuck31 · textwebappsasp
https://www.exploit-db.com/exploits/29240

The provided text describes a cross-site scripting (XSS) vulnerability in Ã?ilem Haber Free Edition, where user-supplied input is not properly sanitized in the 'hata' parameter of 'hata.asp'. An attacker can exploit this to execute arbitrary script code in a user's browser.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Ã?ilem Haber Free Edition
No auth needed
Prerequisites: Access to the vulnerable application URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21511

Scores

EPSS 0.0152
EPSS Percentile 71.4%

Details

Status published
Products (1)
cilem/cilem_haber free_edition
Published Dec 14, 2006
Tracked Since Feb 18, 2026