CVE-2006-6871
eNdonesia 8.4 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6871. PoCs published by z1ckX(ru).
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Endonesia8.4, including XSS, SQL injection, and local file inclusion, with a focus on SQLi for RCE via a web shell. The PoC provides clear examples of exploitable endpoints and payloads.
Description
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewlink operation in mod.php, (2) the intypeid parameter in a showinfo operation in the informasi module in mod.php, (3) the "your Friend" field in friend.php, or (4) the "Main Text" field in admin.php.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Endonesia8.4, including XSS, SQL injection, and local file inclusion, with a focus on SQLi for RCE via a web shell. The PoC provides clear examples of exploitable endpoints and payloads.