CVE-2007-6126
project_alumni <= 1.0.9 - Cross-Site Scripting via Year Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6126. PoCs published by tomplixsee.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Project Alumni v1.0.9 and lower. The SQLi allows unauthorized data extraction, including admin credentials, while the XSS enables arbitrary script execution in the context of the victim's browser.
Description
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Project Alumni v1.0.9 and lower. The SQLi allows unauthorized data extraction, including admin credentials, while the XSS enables arbitrary script execution in the context of the victim's browser.