CVE-2006-3563
Winged Gallery 1.0 - Cross-Site Scripting via Image Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3563. PoCs published by Luny.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Winged Gallery by injecting malicious script tags via the 'image' parameter in thumb.php. The payload bypasses input sanitization to execute arbitrary JavaScript in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Winged Gallery by injecting malicious script tags via the 'image' parameter in thumb.php. The payload bypasses input sanitization to execute arbitrary JavaScript in the context of the affected site.