CVE-2007-4899
Boinc Forum < 5.10.20 - Cross-Site Scripting via Forum ID or Search String Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-4899. PoCs published by Doz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in BOINC 5.10.20, where user-supplied input is not sufficiently sanitized. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search.
Exploits (2)
The provided text describes a cross-site scripting (XSS) vulnerability in BOINC 5.10.20, where user-supplied input is not sufficiently sanitized. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in BOINC 5.10.20, where insufficient input sanitization allows arbitrary script execution in a user's browser context. The example URL demonstrates a potential attack vector but lacks executable exploit code.