CVE-2007-6489
Falcon Series One CMS 1.4.3 - Cross-Site Scripting via Guestbook Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6489. PoCs published by MhZ91.
AI-analyzed exploit summary The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in Falcon CMS, allowing arbitrary code execution via manipulated 'dir[classes]' and 'error' parameters. It also includes a permanent XSS and CSRF exploit for password change.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors.
Exploits (1)
The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in Falcon CMS, allowing arbitrary code execution via manipulated 'dir[classes]' and 'error' parameters. It also includes a permanent XSS and CSRF exploit for password change.