CVE-2004-2130
phpBB 2.0.6 - Cross-Site Scripting via Folder or Mode Variables
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2130. PoCs published by Ben Drysdale.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpBB's 'privmsg.php' script. The vulnerability arises due to insufficient sanitization of URI parameters, allowing arbitrary script execution in the context of the victim's browser.
Description
Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in phpBB's 'privmsg.php' script. The vulnerability arises due to insufficient sanitization of URI parameters, allowing arbitrary script execution in the context of the victim's browser.