CVE-2006-7004
PSY Auction - Cross-Site Scripting via email_request.php user_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-7004. PoCs published by Luny.
AI-analyzed exploit summary The provided text describes input-validation vulnerabilities in PSY Auction, including HTML-injection and SQL-injection. It references a specific URL parameter (`user_id`) that could be exploited but does not include actual exploit code.
Description
Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The provided text describes input-validation vulnerabilities in PSY Auction, including HTML-injection and SQL-injection. It references a specific URL parameter (`user_id`) that could be exploited but does not include actual exploit code.