Exploitation Summary
EIP tracks 2 public exploits for CVE-2003-0375. PoCs published by Knight Commander, Marc Ruef.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in XMB Forum by injecting arbitrary script code via the 'member' parameter in the member.php file. The vulnerability arises due to insufficient sanitization of user-supplied input.
Description
Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in XMB Forum by injecting arbitrary script code via the 'member' parameter in the member.php file. The vulnerability arises due to insufficient sanitization of user-supplied input.
The provided text describes a cross-site scripting (XSS) vulnerability in XMB Forum 1.8, where URL parameters are not adequately sanitized, allowing attacker-supplied script code to execute in the context of a user's browser. The example URL demonstrates how an attacker could inject malicious JavaScript via the 'member' parameter.