CVE-2008-6891
ASP Forum Script - Cross-Site Scripting via forum_id Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-6891. PoCs published by Pouya_Server.
AI-analyzed exploit summary The provided text describes an SQL injection and XSS vulnerability in ASP Forum Script, with an example XSS payload. No actual exploit code is present, only a description and a sample attack URL.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp.
Exploits (3)
The provided text describes an SQL injection and XSS vulnerability in ASP Forum Script, with an example XSS payload. No actual exploit code is present, only a description and a sample attack URL.
The exploit demonstrates an XSS vulnerability in ASP Forum Script by injecting a malicious script tag into the 'forum_id' parameter. It also mentions SQL injection vulnerabilities but does not provide a PoC for them.
This exploit demonstrates an XSS vulnerability in ASP Forum Script by injecting a script tag into the URL parameter. It also mentions SQL injection vulnerabilities but does not provide a PoC for them.