CVE-2008-3511
Softbiz Image Gallery - 'adminhome.php?msg' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
11Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados (XSS) en Softbiz Image Gallery (Photo Gallery) permite a atacantes remotos inyectar web script o HTML a través del parámetro (1) latest en (a) index.php, (b) images.php, (c) suggest_image.php y (d) image_desc.php; y del parámetro (2) msg de index.php, images.php, y suggest_image.php, y (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php y (k) images.php in admin/. NOTA: el vector image_desc.php/msg está cubierto por la CVE-2006-1660. NOTA: El origen de esta información es desconocido; los detalles se han obtenido únicamente de fuentes de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-05 First Exploit
- 2008-08-07 CVE Reserved
- 2008-08-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/44433 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32174 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32176 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32178 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32175 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32177 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32171 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32173 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32170 | 2008-08-05 | |
https://www.exploit-db.com/exploits/32172 | 2008-08-05 | |
http://www.securityfocus.com/bid/30546 | 2024-08-07 | |
http://www.securityfocus.com/bid/30546/exploit | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Softbiz Search vendor "Softbiz" | Image Gallery Search vendor "Softbiz" for product "Image Gallery" | * | - |
Affected
|