CVE-2003-1146
Easy PHP Photo Album 1.0 - Cross-Site Scripting via dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-1146. PoCs published by [email protected].
AI-analyzed exploit summary The provided text describes a HTML injection vulnerability in Easy PHP Photo Album version 1.0, where the 'dir' parameter is not properly sanitized. This allows an attacker to execute arbitrary HTML code in a user's browser, potentially leading to cookie theft or other client-side attacks.
Description
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
Exploits (1)
The provided text describes a HTML injection vulnerability in Easy PHP Photo Album version 1.0, where the 'dir' parameter is not properly sanitized. This allows an attacker to execute arbitrary HTML code in a user's browser, potentially leading to cookie theft or other client-side attacks.