CVE-2005-2441
vbzoom - Cross-Site Scripting via UserName or UserID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-2441. PoCs published by almaster.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in VBZooM Forum by injecting arbitrary JavaScript code via the UserName parameter in the profile.php page. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in VBZooM Forum by injecting arbitrary JavaScript code via the UserName parameter in the profile.php page. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.
This exploit demonstrates a reflected XSS vulnerability in VBZooM Forum by injecting arbitrary JavaScript code via the UserID parameter in login.php. The PoC uses a simple alert to display the user's cookies, proving the lack of input sanitization.