CVE-2006-6778
TimberWolf 1.2.2 - Cross-Site Scripting via shownews.php nid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6778. PoCs published by CorryL.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in TimberWolf 1.2.2 by injecting arbitrary JavaScript code via the 'nid' parameter in shownews.php. The payload bypasses basic sanitization using obfuscation techniques like mixed case and URL encoding.
Description
Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in TimberWolf 1.2.2 by injecting arbitrary JavaScript code via the 'nid' parameter in shownews.php. The payload bypasses basic sanitization using obfuscation techniques like mixed case and URL encoding.