CVE-2008-6988
Ezphotogallery - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) galleryid parameter to gallery.php, and the (2) size or (3) imageid parameters to show.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Khashayar Fereidani · perlwebappsphp
https://www.exploit-db.com/exploits/6428
References (7)
Scores
EPSS
0.0589
EPSS Percentile
90.6%
Details
CWE
CWE-79
Status
published
Products (1)
ezphotogallery/ezphotogallery
2.1
Published
Aug 19, 2009
Tracked Since
Feb 18, 2026