CVE-2008-0541
Gerd Tentler Simple Forum 3.2 - Cross-Site Scripting via Open and Date_Show Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0541. PoCs published by tomplixsee.
AI-analyzed exploit summary The exploit demonstrates XSS and remote file disclosure vulnerabilities in Simple Forum v3.2. The XSS is triggered via unsanitized 'open' and 'date_show' parameters, while the file disclosure leverages path traversal in 'thumbnail.php' to read arbitrary files.
Description
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.
Exploits (1)
The exploit demonstrates XSS and remote file disclosure vulnerabilities in Simple Forum v3.2. The XSS is triggered via unsanitized 'open' and 'date_show' parameters, while the file disclosure leverages path traversal in 'thumbnail.php' to read arbitrary files.