CVE-2008-3559
KAPhotoservice - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by by_casper41 · textwebappsasp
https://www.exploit-db.com/exploits/32184
exploitdb
WORKING POC
VERIFIED
by by_casper41 · textwebappsasp
https://www.exploit-db.com/exploits/32185
References (4)
Scores
EPSS
0.0070
EPSS Percentile
71.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
kaphotoservice/kaphotoservice
Timeline
Published
Aug 08, 2008
Tracked Since
Feb 18, 2026