CVE-2007-2600

TutorialCMS <1.00 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Silentz · perlwebappsphp
https://www.exploit-db.com/exploits/3887

Scores

EPSS 0.1158
EPSS Percentile 93.7%

Details

Status published
Products (1)
wavelink_media/tutorialcms < 1.00
Published May 11, 2007
Tracked Since Feb 18, 2026