CVE-2007-1905
Pineapple Technologies Quizshock < 1.6.1 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by John Martinelli · textwebappsphp
https://www.exploit-db.com/exploits/29824
References (7)
Scores
EPSS
0.0682
EPSS Percentile
91.2%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
pineapple_technologies/quizshock
< 1.6.1
Timeline
Published
Apr 10, 2007
Tracked Since
Feb 18, 2026