CVE-2005-2569
funkboard < 0.66f - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2005-2569. PoCs published by rgod.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in FunkBoard due to improper input sanitization. The PoC provides URLs with injected script tags to execute arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.
Exploits (6)
This exploit demonstrates multiple XSS vulnerabilities in FunkBoard due to improper input sanitization. The PoC provides URLs with injected script tags to execute arbitrary JavaScript in the context of the affected site.
This exploit demonstrates multiple XSS vulnerabilities in FunkBoard's register.php by injecting arbitrary JavaScript via unsanitized input parameters. The PoC uses script tags to trigger an alert with the user's cookies, proving the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in FunkBoard by injecting arbitrary JavaScript code via the 'fbusername' and 'fbpassword' parameters in the profile.php page. The PoC uses a simple alert to display the user's cookies, proving the vulnerability.
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in FunkBoard due to insufficient input sanitization. The PoC provides URLs that inject arbitrary JavaScript code to steal cookie-based authentication credentials.
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in FunkBoard due to insufficient input sanitization. The PoC provides URLs with injected JavaScript to steal cookies.
This exploit demonstrates multiple cross-site scripting (XSS) vulnerabilities in FunkBoard due to improper input sanitization. The PoC shows how arbitrary script code can be executed in the context of the affected site by injecting malicious scripts into the 'fbusername' and 'fbpassword' parameters.