Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-6746. PoCs published by Mr_KaLiMaN.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in Xt-News, including XSS and SQL injection, but does not contain actual exploit code. It references a generic example URL for XSS exploitation.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
Exploits (2)
The provided text describes multiple input-validation vulnerabilities in Xt-News, including XSS and SQL injection, but does not contain actual exploit code. It references a generic example URL for XSS exploitation.
The provided text describes a vulnerability in Xt-News version 0.1, which is prone to XSS and SQL injection due to insufficient input sanitization. It includes a generic example URL demonstrating the XSS vulnerability but lacks actual exploit code.