CVE-2008-2698
Web-album Webalbum - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
web-album/webalbum
Timeline
Published
Jun 13, 2008
Tracked Since
Feb 18, 2026