CVE-2006-2187
zenphoto < 1.0.1_beta - Cross-Site Scripting via i.php a Parameter and index.php album/image Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-2187. PoCs published by zone14.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in Zenphoto versions prior to 1.0.3 by injecting malicious script tags via the 'album' and 'image' parameters in the URL. The provided URLs show how arbitrary JavaScript can be executed in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.
Exploits (2)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in Zenphoto versions prior to 1.0.3 by injecting malicious script tags via the 'album' and 'image' parameters in the URL. The provided URLs show how arbitrary JavaScript can be executed in the context of the affected site.
The exploit demonstrates a reflected XSS vulnerability in Zenphoto versions prior to 1.0.3 by injecting a malicious script via the 'a' parameter in the URL. The payload executes arbitrary JavaScript in the context of the affected site.