CVE-2007-0846
Open Tibia Server CMS <= 2.1.5 - Cross-Site Scripting via Forum Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0846. PoCs published by GregStar.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in OTSCMS 2.1.5. The SQLi allows unauthorized data extraction via a crafted 'id' parameter, while the XSS executes arbitrary JavaScript through the 'name' parameter.
Description
Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in OTSCMS 2.1.5. The SQLi allows unauthorized data extraction via a crafted 'id' parameter, while the XSS executes arbitrary JavaScript through the 'name' parameter.