CVE-2006-0407
AZ Bulletin Board <= 1.1.00 - Cross-Site Scripting via Nickname Parameter or Topic Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0407. PoCs published by Roozbeh Afrasiabi.
AI-analyzed exploit summary This exploit demonstrates HTML injection vulnerabilities in AZbb due to insufficient input sanitization. It provides example URLs with malicious scripts that execute in the context of the affected website, potentially leading to credential theft or site manipulation.
Description
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.
Exploits (1)
This exploit demonstrates HTML injection vulnerabilities in AZbb due to insufficient input sanitization. It provides example URLs with malicious scripts that execute in the context of the affected website, potentially leading to credential theft or site manipulation.