CVE-2008-6700
Butterflymedia Butterfly Organizer - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/5797
Scores
EPSS
0.0227
EPSS Percentile
84.4%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
butterflymedia/butterfly_organizer
n/a/n/a
Timeline
Published
Apr 10, 2009
Tracked Since
Feb 18, 2026