CVE-2006-3036
35mmslidegallery 6.0 - Cross-Site Scripting via imgdir w h and t Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-3036. PoCs published by black-cod3.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in 35mmslidegallery by injecting arbitrary script code via unsanitized input parameters (w, h, t) in popup.php. The PoC uses simple script tags to trigger an alert, confirming the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.
Exploits (2)
The exploit demonstrates multiple XSS vulnerabilities in 35mmslidegallery by injecting arbitrary script code via unsanitized input parameters (w, h, t) in popup.php. The PoC uses simple script tags to trigger an alert, confirming the vulnerability.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in 35mmslidegallery by injecting arbitrary JavaScript code via the 'imgdir' parameter. The PoC uses a simple alert script to confirm the vulnerability.