Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-2755. PoCs published by nukedx.
AI-analyzed exploit summary The exploit demonstrates multiple file inclusion vulnerabilities in UBBThreads 5.x and 6.x, allowing remote attackers to include arbitrary files or execute code via crafted GET requests. It also includes an XSS vulnerability example.
Description
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.
Exploits (1)
The exploit demonstrates multiple file inclusion vulnerabilities in UBBThreads 5.x and 6.x, allowing remote attackers to include arbitrary files or execute code via crafted GET requests. It also includes an XSS vulnerability example.