CVE-2007-6136

M2Scripts MySpace Scripts Poll Creator - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Doz · textwebappsphp
https://www.exploit-db.com/exploits/30799

Scores

EPSS 0.0043
EPSS Percentile 62.0%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

m2scripts/my_space_scripts_poll_creator

Timeline

Published Nov 27, 2007
Tracked Since Feb 18, 2026