CVE-2008-6211

Mcgallery - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net mcGallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the lang parameter to (1) admin.php, (2) index.php, (3) sess.php, (4) stats.php, (5) detail.php, (6) resize.php, and (7) show.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (7)

exploitdb WORKING POC VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31599
exploitdb WORKING POC VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31602
exploitdb WORKING POC VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31598
exploitdb WORKING POC VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31601
exploitdb WORKING POC VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31597
exploitdb WORKING POC VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31600
exploitdb WRITEUP VERIFIED
by K-9999 · textwebappsphp
https://www.exploit-db.com/exploits/31596

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28587
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41637

Scores

EPSS 0.0023
EPSS Percentile 45.7%

Details

CWE
CWE-79
Status published
Products (1)
mcgallerypro/mcgallery 1.1
Published Feb 20, 2009
Tracked Since Feb 18, 2026