iss4m

2 exploits Active since Jul 2006
CVE-2006-3476 EXPLOITDB text WORKING POC
phpwebgallery - Cross-Site Scripting via comments.php Keyword Parameter
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
CVE-2006-7136 EXPLOITDB text WORKING POC
PHP Poll Creator < 1.04 - Remote File Inclusion via relativer_pfad Parameter
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.