Exploitation Summary
EIP tracks 4 public exploits for CVE-2006-6928. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in Grandora Rialto, including SQL injection and XSS, due to insufficient sanitization of user-supplied data. It includes a sample XSS payload but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Rialto 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) listmain.asp or (b) searchmain.asp, the (2) the Keyword parameter to (c) searchkey.asp, or the (3) refno parameter to (d) forminfo.asp.
Exploits (4)
The provided text describes multiple input-validation vulnerabilities in Grandora Rialto, including SQL injection and XSS, due to insufficient sanitization of user-supplied data. It includes a sample XSS payload but lacks executable exploit code.
The provided text describes multiple input-validation vulnerabilities in Grandora Rialto, including SQL injection and XSS, but does not include functional exploit code. It references a generic XSS example without technical details.
The provided text describes a vulnerability in Grandora Rialto version 1.6, highlighting SQL injection and XSS issues due to insufficient input sanitization. It includes a generic XSS example but lacks functional exploit code.
The provided text describes SQL injection and XSS vulnerabilities in Grandora Rialto 1.6 due to insufficient input sanitization. It includes a generic XSS example but lacks executable exploit code.