Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3590. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in b1gBB 2.24.0. The SQLi exploits retrieve user credentials via union-based injection, while the XSS exploit executes arbitrary JavaScript via a crafted user parameter.
Description
Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in b1gBB 2.24.0. The SQLi exploits retrieve user credentials via union-based injection, while the XSS exploit executes arbitrary JavaScript via a crafted user parameter.