CVE-2007-5983

Justin Hagstrom AutoIndex <2.2.3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

Exploits (1)

exploitdb WORKING POC VERIFIED
by L4teral · textwebappsphp
https://www.exploit-db.com/exploits/30754

Scores

EPSS 0.0952
EPSS Percentile 92.7%

Classification

CWE
CWE-79
Status draft

Affected Products (14)

justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script
justin_hagstrom/autoindex_php_script

Timeline

Published Nov 15, 2007
Tracked Since Feb 18, 2026