CVE-2008-1296
EncapsGallery 1.11.2 - Cross-Site Scripting via File Parameter in Watermark Scripts
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-1296. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in EncapsGallery 1.11.2 by injecting arbitrary JavaScript code via the 'file' parameter in watermark.php. The PoC uses a simple alert() payload to confirm the vulnerability.
Description
Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote attackers to inject arbitrary web script or HTML via the file parameter to (1) watermark.php and (2) catalog_watermark.php in core/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in EncapsGallery 1.11.2 by injecting arbitrary JavaScript code via the 'file' parameter in watermark.php. The PoC uses a simple alert() payload to confirm the vulnerability.
This exploit demonstrates a reflected XSS vulnerability in EncapsGallery 1.11.2 by injecting a script tag into the 'file' parameter of catalog_watermark.php, which executes arbitrary JavaScript in the context of the affected site.