Exploitation Summary
EIP tracks 6 public exploits for CVE-2008-3565. PoCs published by sl4xUz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'area' parameter in week.php.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (6)
The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'area' parameter in week.php.
The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'area' parameter in report.php.
The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. It includes a sample URL demonstrating the vulnerability but lacks actual exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'area' parameter in help.php.
The provided text describes a cross-site scripting (XSS) vulnerability in MRBS 1.2.6, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'area' parameter in day.php.