CVE-2005-0307
MercuryBoard 1.1.1 - Cross-Site Scripting via Multiple Index.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0307. PoCs published by Alberto Trivero.
AI-analyzed exploit summary The exploit demonstrates multiple input validation vulnerabilities in MercuryBoard, including XSS and SQL injection. The XSS payloads inject JavaScript to steal cookies, while the SQL injection extracts user credentials from the database.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.
Exploits (1)
The exploit demonstrates multiple input validation vulnerabilities in MercuryBoard, including XSS and SQL injection. The XSS payloads inject JavaScript to steal cookies, while the SQL injection extracts user credentials from the database.