Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1827. PoCs published by Cheng Peng Su.
AI-analyzed exploit summary This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in YaBB and YaBB SE due to improper validation of URI-supplied user input. The PoC includes crafted BBCode tags that execute JavaScript when rendered.
Description
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
Exploits (1)
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in YaBB and YaBB SE due to improper validation of URI-supplied user input. The PoC includes crafted BBCode tags that execute JavaScript when rendered.