27809Third-party advisory
http://secunia.com/advisories/27809 CVE-2007-6135
PHPSlideShow 0.9.9 - 'Directory' Cross-Site Scripting
Record summary
CVE-2007-6135 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: this issue was originally reported for toonchapter8.php, but this is probably a site-specific name, since the PHPSlideShow distribution does not contain that file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHPSlideShow 0.9.9 - 'Directory' Cross-Site ScriptingExploitDB exploitby Jose Luis Gongora FernandezNot analyzed1 file
References
10packetstormsecurity.org
http://www.packetstormsecurity.org/0711-exploits/phpslideshow-xss.txt 20071126 PHPSlideShow (toonchapter8.php) Cross-Site Scripting Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/484192/100/0/threaded 20071127 PHPSlideShow XSS Updatemailing list
http://www.securityfocus.com/archive/1/484289/100/0/threaded 20080416 Re: PHPSlideShow (toonchapter8.php) Cross-Site Scripting Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/490968/100/0/threaded 26575vdb entry
http://www.securityfocus.com/bid/26575 26576vdb entry
http://www.securityfocus.com/bid/26576 ADV-2007-3992vdb entry
http://www.vupen.com/english/advisories/2007/3992 phpslideshow-directory-xss(38638)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38638 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6135