CVE-2007-6374
bitweaver < 2.0.0 - Cross-Site Scripting via PATH_INFO to users/register.php or search/index.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-6374. PoCs published by Doz.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in Bitweaver, including XSS, HTML injection, and SQL injection, but does not contain actual exploit code. It references a URL for an XSS vulnerability without further details.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) search/index.php, or an editcomments action in (3) wiki/index.php or (4) forums/index.php. NOTE: the error parameter to users/login.php is covered by CVE-2006-3103.
Exploits (2)
The provided text describes multiple input-validation vulnerabilities in Bitweaver, including XSS, HTML injection, and SQL injection, but does not contain actual exploit code. It references a URL for an XSS vulnerability without further details.
The provided text describes multiple input-validation vulnerabilities in Bitweaver, including XSS, HTML injection, and SQL injection, but does not contain actual exploit code. It references CVE-2007-6374 and provides a high-level overview of potential attacks.