CVE-2008-1347
MyioSoft EasyGallery <= 5.0tr - Cross-Site Scripting via PATH_INFO or q Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1347. PoCs published by JosS.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in EasyGallery <= 5.0tr, including SQL injection and XSS. It provides specific exploit URLs and payloads for both SQLi and XSS attacks.
Description
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the q parameter in an about action to the help system.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in EasyGallery <= 5.0tr, including SQL injection and XSS. It provides specific exploit URLs and payloads for both SQLi and XSS attacks.