Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) path and (2) download parameters.
Exploits (1)
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35813
Various Sources x_refsource_misc
http://pridels-team.blogspot.com/2007/08/snif-xss-vuln.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/38701
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/25212
Scores
EPSS
0.0046
EPSS Percentile
64.1%
Details
Status
published
Products (1)
kai_blankenhorn_bitfolge/simple_and_nice_index_file
< 1.5.2
Published
Aug 09, 2007
Tracked Since
Feb 18, 2026