CVE-2008-3566
ZoneO-soft freeForum 1.7 - Cross-Site Scripting via acuparam Parameter or PATH_INFO
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3566. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in freeForum 1.7 by injecting arbitrary JavaScript code via unsanitized user input in URL parameters. The PoC includes multiple attack vectors to trigger the XSS payload.
Description
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in freeForum 1.7 by injecting arbitrary JavaScript code via unsanitized user input in URL parameters. The PoC includes multiple attack vectors to trigger the XSS payload.