CVE-2006-2210
321soft php-gallery 0.9 - Cross-Site Scripting via Path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2210. PoCs published by d4igoro.
AI-analyzed exploit summary The provided text describes an information-disclosure and XSS vulnerability in PhP-Gallery due to improper input sanitization. It includes a sample URL demonstrating the XSS vector but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability.
Exploits (1)
The provided text describes an information-disclosure and XSS vulnerability in PhP-Gallery due to improper input sanitization. It includes a sample URL demonstrating the XSS vector but lacks executable exploit code.