Vulnerabilities > CVE-2006-1645 - HTML Injection vulnerability in ReloadCMS User-Agent
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitrary web script or HTML and gain leverage to execute arbitrary PHP code via the User-Agent HTTP header, which is displayed by admin/modules/general/statistic.php in the administration panel.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Exploit-Db
description | ReloadCMS <= 1.2.5 Cross Site Scripting / Remote Code Execution Exploit. CVE-2006-1645. Webapps exploit for php platform |
id | EDB-ID:1631 |
last seen | 2016-01-31 |
modified | 2006-04-02 |
published | 2006-04-02 |
reporter | rgod |
source | https://www.exploit-db.com/download/1631/ |
title | ReloadCMS <= 1.2.5 - Cross-Site Scripting / Remote Code Execution Exploit |