CVE-2012-4873
GNUBoard < 4.34 - Cross-Site Scripting via File Download Filename Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4873. PoCs published by wh1ant.
AI-analyzed exploit summary This exploit demonstrates an HTML-injection vulnerability in Gnuboard versions prior to 4.34.21. The vulnerability allows attacker-supplied HTML and script code to execute in the context of the affected website, potentially leading to cookie theft or site rendering manipulation.
Description
Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.
Exploits (1)
This exploit demonstrates an HTML-injection vulnerability in Gnuboard versions prior to 4.34.21. The vulnerability allows attacker-supplied HTML and script code to execute in the context of the affected website, potentially leading to cookie theft or site rendering manipulation.