CVE-2005-0307

MercuryBoard 1.1.1 - Cross-Site Scripting via Multiple Index.php Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-0307. PoCs published by Alberto Trivero.

AI-analyzed exploit summary The exploit demonstrates multiple input validation vulnerabilities in MercuryBoard, including XSS and SQL injection. The XSS payloads inject JavaScript to steal cookies, while the SQL injection extracts user credentials from the database.

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alberto Trivero · textwebappsphp
https://www.exploit-db.com/exploits/25059

The exploit demonstrates multiple input validation vulnerabilities in MercuryBoard, including XSS and SQL injection. The XSS payloads inject JavaScript to steal cookies, while the SQL injection extracts user credentials from the database.

Classification
Working Poc 90%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Reliable
Target: MercuryBoard (version not specified)
No auth needed
Prerequisites: Access to the target MercuryBoard instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110661795632354&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19050
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12359

Scores

EPSS 0.0174
EPSS Percentile 74.7%

Details

Status published
Products (2)
mercuryboard/mercuryboard 1.1
mercuryboard/mercuryboard 1.1.1
Published Jan 25, 2005
Tracked Since Feb 18, 2026