CVE-2008-2997
Gravity Board X 2.0 Beta - Cross-Site Scripting via Subject Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2997. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Gravity Board X 2.0 Beta via the thread title field and an SQL injection vulnerability in the search and viewboard functionalities when magic_quotes_gpc is disabled.
Description
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Gravity Board X 2.0 Beta via the thread title field and an SQL injection vulnerability in the search and viewboard functionalities when magic_quotes_gpc is disabled.