CVE-2008-3511
Softbiz Image Gallery - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 9 public exploits for CVE-2008-3511. PoCs published by sl4xUz.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input via the 'latest' and 'msg' parameters in 'suggest_image.php' is not properly sanitized. This allows arbitrary script execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (9)
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input via the 'latest' and 'msg' parameters in 'suggest_image.php' is not properly sanitized. This allows arbitrary script execution in the context of the affected site.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input via the 'latest' and 'msg' parameters is not properly sanitized. This allows arbitrary script execution in the context of the affected site.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input via the 'latest' and 'msg' parameters in 'image_desc.php' is not properly sanitized. This allows arbitrary script execution in the context of the affected site.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input via the 'latest' and 'msg' parameters in images.php is not properly sanitized. This allows arbitrary script execution in the context of the affected site.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'msg' parameter in the admin/config.php page.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where the 'msg' parameter in 'cleanup.php' is not properly sanitized. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'msg' parameter in the changepassword.php page.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where insufficient sanitization of user-supplied data allows arbitrary script execution in the context of the affected site. The example URL demonstrates the vulnerability by injecting an XSS payload into the 'msg' parameter.
The provided text describes a cross-site scripting (XSS) vulnerability in Softbiz Photo Gallery, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'msg' parameter.