CVE-2008-5193
Philboard 1.14 and 1.2 - Cross-Site Scripting via search.asp searchterms Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5193. PoCs published by Bl@ckbe@rD.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in philboard v1.14. The SQLi uses a blind injection technique, while the XSS exploit leverages a simple script tag to steal cookies.
Description
Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in philboard v1.14. The SQLi uses a blind injection technique, while the XSS exploit leverages a simple script tag to steal cookies.