CVE-2007-6455
Mambo 4.6.2 - Cross-Site Scripting via Itemid or Option Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6455. PoCs published by Beenu Arora.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Mambo CMS by injecting arbitrary JavaScript via unsanitized URL parameters. The PoC uses the 'option' and 'Itemid' parameters to trigger script execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in Mambo CMS by injecting arbitrary JavaScript via unsanitized URL parameters. The PoC uses the 'option' and 'Itemid' parameters to trigger script execution in the context of the affected site.