CVE-2008-6924
eSyndiCat Directory 2.2 - Cross-Site Scripting via Register Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6924. PoCs published by Fugitif.
AI-analyzed exploit summary This exploit demonstrates multiple reflected XSS vulnerabilities in eSyndiCat Pro 2.2 by injecting arbitrary JavaScript into the 'register.php' page via unsanitized user input fields (username, email, password, etc.). The PoC uses simple script tags to trigger alerts, proving the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register parameters.
Exploits (1)
This exploit demonstrates multiple reflected XSS vulnerabilities in eSyndiCat Pro 2.2 by injecting arbitrary JavaScript into the 'register.php' page via unsanitized user input fields (username, email, password, etc.). The PoC uses simple script tags to trigger alerts, proving the vulnerability.