Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6727. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit leverages a log injection vulnerability in Ultimate PHP Board <= 2.2.1 to escalate privileges from a regular user to admin. It injects a malicious User-Agent header containing JavaScript that triggers an XMLHttpRequest to modify the user's privileges when the admin views the logs.
Description
Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
Exploits (1)
This exploit leverages a log injection vulnerability in Ultimate PHP Board <= 2.2.1 to escalate privileges from a regular user to admin. It injects a malicious User-Agent header containing JavaScript that triggers an XMLHttpRequest to modify the user's privileges when the admin views the logs.