Vulnerabilities > CVE-2006-5770 - Cross-Site Scripting vulnerability in Mobile

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ac4p
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Newnews, (3) lBlok, and (4) foooot parameter in (a) index.php; Newnews, (5) newmsgs, and Bloks parameter in (b) MobileNews.php; Newnews parameter in (c) polls.php; (6) cats parameter in (d) send.php; (7) footer parameter in (e) up.php; and (8) pagenav parameter in (f) cp/index.php.

Vulnerable Configurations

Part Description Count
Application
Ac4P
1

Exploit-Db

  • descriptionac4p Mobile MobileNews.php Multiple Parameter XSS. CVE-2006-5770. Webapps exploit for php platform
    idEDB-ID:28901
    last seen2016-02-03
    modified2006-11-03
    published2006-11-03
    reporterAL-garnei
    sourcehttps://www.exploit-db.com/download/28901/
    titleac4p Mobile MobileNews.php Multiple Parameter XSS
  • descriptionac4p Mobile index.php Multiple Parameter XSS. CVE-2006-5770. Webapps exploit for php platform
    idEDB-ID:28900
    last seen2016-02-03
    modified2006-11-03
    published2006-11-03
    reporterAL-garnei
    sourcehttps://www.exploit-db.com/download/28900/
    titleac4p Mobile index.php Multiple Parameter XSS
  • descriptionac4p Mobile send.php cats Parameter XSS. CVE-2006-5770. Webapps exploit for php platform
    idEDB-ID:28903
    last seen2016-02-03
    modified2006-11-03
    published2006-11-03
    reporterAL-garnei
    sourcehttps://www.exploit-db.com/download/28903/
    titleac4p Mobile send.php cats Parameter XSS
  • descriptionac4p Mobile polls.php Multiple Parameter XSS. CVE-2006-5770. Webapps exploit for php platform
    idEDB-ID:28902
    last seen2016-02-03
    modified2006-11-03
    published2006-11-03
    reporterAL-garnei
    sourcehttps://www.exploit-db.com/download/28902/
    titleac4p Mobile polls.php Multiple Parameter XSS
  • descriptionac4p Mobile up.php Multiple Parameter XSS. CVE-2006-5770. Webapps exploit for php platform
    idEDB-ID:28904
    last seen2016-02-03
    modified2006-11-03
    published2006-11-03
    reporterAL-garnei
    sourcehttps://www.exploit-db.com/download/28904/
    titleac4p Mobile up.php Multiple Parameter XSS
  • descriptionac4p Mobile cp/index.php pagenav Parameter XSS. CVE-2006-5770. Webapps exploit for php platform
    idEDB-ID:28905
    last seen2016-02-03
    modified2006-11-03
    published2006-11-03
    reporterAL-garnei
    sourcehttps://www.exploit-db.com/download/28905/
    titleac4p Mobile cp/index.php pagenav Parameter XSS