CVE-2008-7133
EasyImageCatalogue 1.3.1 - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2008-7133. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in EasyImageCatalogue 1.31 by injecting a script tag via the 'dir' parameter in thumber.php. The lack of input sanitization allows arbitrary JavaScript execution in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to thumber.php, and the d parameter to (4) describe.php and (5) addcomment.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (4)
This exploit demonstrates a reflected XSS vulnerability in EasyImageCatalogue 1.31 by injecting a script tag via the 'dir' parameter in thumber.php. The lack of input sanitization allows arbitrary JavaScript execution in the context of the affected site.
This exploit demonstrates multiple XSS vulnerabilities in EasyImageCatalogue 1.31 by injecting arbitrary JavaScript via the 'search' and 'd' parameters. The PoC uses simple script tags to trigger an alert, confirming the vulnerability.
The provided text describes a cross-site scripting (XSS) vulnerability in onlinetools.org EasyImageCatalogue 1.31. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a cross-site scripting (XSS) vulnerability in onlinetools.org EasyImageCatalogue 1.31. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.