CVE-2004-1965

NUCLEI

Open Bulletin Board <= 1.0.6 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2004-1965. PoCs published by JeiAr, GulfTech Security. A Nuclei detection template is also available.

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in OpenBB due to improper input sanitization. It includes a sample XSS payload but lacks executable exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.

Exploits (5)

exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24054

The provided text describes SQL injection and XSS vulnerabilities in OpenBB due to improper input sanitization. It includes a sample XSS payload but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: OpenBB (version not specified)
No auth needed
Prerequisites: Access to a vulnerable OpenBB instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24053

This is a vulnerability writeup describing SQL injection and XSS vulnerabilities in OpenBB. It provides a high-level overview of the issues but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: OpenBB (version not specified)
No auth needed
Prerequisites: Access to the vulnerable OpenBB instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24052

This is a vulnerability writeup describing SQL injection and XSS vulnerabilities in OpenBB. It provides details on the issues but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: OpenBB (version not specified)
No auth needed
Prerequisites: Access to the vulnerable OpenBB instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by JeiAr · textwebappsphp
https://www.exploit-db.com/exploits/24055

This is a vulnerability writeup describing SQL injection and XSS vulnerabilities in OpenBB. It does not contain exploit code but provides technical details and example attack vectors.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: OpenBB (version not specified)
No auth needed
Prerequisites: Access to the vulnerable OpenBB instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/43811

This is a detailed vulnerability writeup for CVE-2004-1965, describing multiple issues in OpenBB <= 1.0.6, including XSS, SQL injection, and arbitrary command execution via unsafe GET requests. It provides examples of vulnerable endpoints and code snippets but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Xss | Sqli | Other
Complexity
Trivial
Reliability
Theoretical
Target: OpenBB <= 1.0.6
No auth needed
Prerequisites: Access to vulnerable OpenBB instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Open Bulletin Board (OpenBB) v1.0.6 - Open Redirect/XSS
MEDIUMby ctflearner

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15966
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10214
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108301983206107&w=2
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11481
Exploit, Vendor Advisory vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1009935

Scores

EPSS 0.0027
EPSS Percentile 50.4%

Details

Status published
Published Apr 25, 2004
Tracked Since Feb 18, 2026