CVE-2008-3786
PICTURESPRO Photo Cart 3.9 - Cross-Site Scripting via qtitle Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3786. PoCs published by Tyler Trioxide.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Photo Cart 3.9 by injecting a malicious script into the 'Gallery or event name' field. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookie-based authentication credentials.
Description
Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka "Gallery or event name" field) in a search action.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Photo Cart 3.9 by injecting a malicious script into the 'Gallery or event name' field. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookie-based authentication credentials.