CVE-2008-4336
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting via apa_album_ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4336. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Atomic Photo Album 1.1.0pre4. The SQLi extracts database version, name, and user, while the XSS executes arbitrary JavaScript via the apa_album_ID parameter.
Description
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Atomic Photo Album 1.1.0pre4. The SQLi extracts database version, name, and user, while the XSS executes arbitrary JavaScript via the apa_album_ID parameter.