28573Third-party advisory
http://secunia.com/advisories/28573 CVE-2008-0400
Singapore 0.10.1 Modern Template - 'gallery' Cross-Site Scripting
Record summary
CVE-2008-0400 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSingapore 0.10.1 Modern Template - 'gallery' Cross-Site ScriptingExploitDB exploitby trewNot analyzed1 file
References
5trew.icenetx.net
http://trew.icenetx.net/toolz/advisory-singapore-modern-template.txt 27382vdb entry
http://www.securityfocus.com/bid/27382 ADV-2008-0234vdb entry
http://www.vupen.com/english/advisories/2008/0234 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0400