CVE-2007-6560
Logaholic - Cross-Site Scripting via newconfname or conf Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-6560. PoCs published by malibu.r.
AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in Logaholic via the 'newconfname' POST parameter in profiles.php. The payload injects a script tag to trigger a JavaScript alert, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.
Exploits (2)
This exploit demonstrates an XSS vulnerability in Logaholic via the 'newconfname' POST parameter in profiles.php. The payload injects a script tag to trigger a JavaScript alert, confirming the vulnerability.
The provided text describes multiple input-validation vulnerabilities in Logaholic, including SQL injection, XSS, and HTML injection. It includes a sample XSS payload but lacks executable exploit code.