CVE-2005-1614
Ultimate PHP Board 1.8-1.9.6 - Cross-Site Scripting via viewforum.php postorder Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-1614. PoCs published by Morinex Eneco.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Ultimate PHP Board due to insufficient input sanitization. The PoC URL injects a script tag that executes arbitrary JavaScript, specifically an alert displaying the document.cookie value.
Description
Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Ultimate PHP Board due to insufficient input sanitization. The PoC URL injects a script tag that executes arbitrary JavaScript, specifically an alert displaying the document.cookie value.