CVE-2004-0319
ezboard 7.3u - Cross-Site Scripting via Font Tag Background URL
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0319. PoCs published by Cheng Peng Su.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in ezboard, where malicious JavaScript can be embedded within [font] tags to execute arbitrary code in the context of the victim's browser session.
Description
Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in ezboard, where malicious JavaScript can be embedded within [font] tags to execute arbitrary code in the context of the victim's browser session.