CVE-2005-2539
FlatNuke 2.5.5 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-2539. PoCs published by rgod.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in FlatNuke by injecting malicious JavaScript via unsanitized input parameters in the 'structure.php' file. The PoC uses simple script tags to trigger an alert with the victim's cookies.
Description
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.
Exploits (2)
This exploit demonstrates multiple XSS vulnerabilities in FlatNuke by injecting malicious JavaScript via unsanitized input parameters in the 'structure.php' file. The PoC uses simple script tags to trigger an alert with the victim's cookies.
This exploit demonstrates multiple XSS vulnerabilities in FlatNuke by injecting script tags into URL parameters. The PoC uses simple JavaScript alerts to confirm cookie theft potential.