CVE-2008-6631
BlogPHP 2.0 - Cross-Site Scripting via User Parameter in Sendmessage Action and Username Parameter in Registration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6631. PoCs published by David Sopas Ferreira.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in BlogPHP 2.0, including XSS, HTML injection, and cookie manipulation. It includes a sample URL demonstrating an XSS attack vector but lacks executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user, different vectors than CVE-2008-0679.
Exploits (1)
The provided text describes multiple input-validation vulnerabilities in BlogPHP 2.0, including XSS, HTML injection, and cookie manipulation. It includes a sample URL demonstrating an XSS attack vector but lacks executable exploit code.