CVE-2008-0436
PD9 Software MegaBBS 1.5.14b - Cross-Site Scripting via Profile Upload Target Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0436. PoCs published by Doz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in MegaBBS 1.5.14b, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could exploit this issue to execute arbitrary script code in a user's browser.
Description
Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in MegaBBS 1.5.14b, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could exploit this issue to execute arbitrary script code in a user's browser.