CVE-2008-2965
JaxUltraBB < 2.0 - Cross-Site Scripting via Forum Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2965. PoCs published by CWH Underground.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in JaxUltraBB <= 2.0 via the 'user' parameter in viewprofile.php, allowing arbitrary file reads using path traversal. It also includes a reflected XSS vulnerability in viewforum.php via the 'forum' parameter.
Description
Cross-site scripting (XSS) vulnerability in viewforum.php in JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in JaxUltraBB <= 2.0 via the 'user' parameter in viewprofile.php, allowing arbitrary file reads using path traversal. It also includes a reflected XSS vulnerability in viewforum.php via the 'forum' parameter.