r57shell

2 exploits Active since Mar 2006
CVE-2006-1324 EXPLOITDB text WORKING POC
Woltlab Burning Board < 1.0.2pl2e_lite - Cross-Site Scripting via errormsg Parameter
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
CVE-2006-1215 EXPLOITDB text WORKING POC
Woltlab Burning Board 2.3.4 - Cross-Site Scripting via Percent Parameter
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.