CVE-2002-1429

endity.com ShoutBOX - Cross-Site Scripting via Site Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1429. PoCs published by delusion.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in shoutBOX due to insufficient input sanitization. Attackers can inject arbitrary HTML and script code via the 'Site URL' form field, leading to code execution in the context of the victim's browser.

Description

Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by delusion · textwebappsphp
https://www.exploit-db.com/exploits/21668

This exploit demonstrates a cross-site scripting (XSS) vulnerability in shoutBOX due to insufficient input sanitization. Attackers can inject arbitrary HTML and script code via the 'Site URL' form field, leading to code execution in the context of the victim's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: shoutBOX (version not specified)
No auth needed
Prerequisites: Access to the shoutBOX form field
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9739.php
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5354
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-07/0389.html

Scores

EPSS 0.0661
EPSS Percentile 93.2%

Details

Status published
Products (1)
endity.com/shoutbox 1.2
Published Apr 11, 2003
Tracked Since Feb 18, 2026