CVE-2007-6560
Logaholic <2.0 RC8 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by malibu.r · textwebappsphp
https://www.exploit-db.com/exploits/30932
References (8)
Scores
EPSS
0.0075
EPSS Percentile
72.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
logaholic/logaholic
Timeline
Published
Dec 28, 2007
Tracked Since
Feb 18, 2026