Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2966. PoCs published by CWH Underground.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in JaxUltraBB <= 2.0 via the 'user' parameter in viewprofile.php, allowing arbitrary file reads using path traversal. It also includes a reflected XSS vulnerability in viewforum.php via the 'forum' parameter.
Description
Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the user parameter. party information.
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in JaxUltraBB <= 2.0 via the 'user' parameter in viewprofile.php, allowing arbitrary file reads using path traversal. It also includes a reflected XSS vulnerability in viewforum.php via the 'forum' parameter.