CVE-2007-3963
UseBB 1.0.7 - Cross-Site Scripting via PATH_INFO in Install Upgrade Scripts
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-3963. PoCs published by s4mi.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in UseBB 1.0.7 by injecting a script tag into the URL path, which executes arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.
Exploits (2)
This exploit demonstrates a reflected XSS vulnerability in UseBB 1.0.7 by injecting a script tag into the URL path, which executes arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a reflected XSS vulnerability in UseBB 1.0.7 by injecting a malicious script into the URL path, which executes arbitrary JavaScript in the context of the affected site.