CVE-2007-6110
htdig 3.2.0b6 - Cross-Site Scripting via htsearch sort Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6110. PoCs published by Michael Skibbe.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in ht://Dig by injecting a malicious script into the 'sort' parameter of the search query. The vulnerability arises due to insufficient sanitization of user-supplied input.
Description
Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in ht://Dig by injecting a malicious script into the 'sort' parameter of the search query. The vulnerability arises due to insufficient sanitization of user-supplied input.