CVE-2010-2463
Jamroom < 4.1.9 - Cross-Site Scripting via Forum Post ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2463. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Jamroom by injecting arbitrary JavaScript via unsanitized input in the forum.php URL parameters. The PoC uses a null byte and script tags to bypass input validation and execute an alert with the document.cookie.
Description
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Jamroom by injecting arbitrary JavaScript via unsanitized input in the forum.php URL parameters. The PoC uses a null byte and script tags to bypass input validation and execute an alert with the document.cookie.