Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4907. PoCs published by Bogdan Calin.
AI-analyzed exploit summary The exploit demonstrates an XSS vulnerability in Zenphoto 1.3 by injecting a malicious script via the 'from' parameter in the admin.php file. The payload triggers a JavaScript prompt, confirming the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
Exploits (1)
The exploit demonstrates an XSS vulnerability in Zenphoto 1.3 by injecting a malicious script via the 'from' parameter in the admin.php file. The payload triggers a JavaScript prompt, confirming the vulnerability.