CVE-2011-4806

phpalbum < 0.4.1.16 - Cross-Site Scripting via var1 or keyword Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4806. PoCs published by BHG Security Center.

AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities in PHP Photo Album <= 0.4.1.16, including XSS, local file disclosure, and PHP code injection. It provides proof-of-concept URLs but does not include executable exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) var1 and (2) keyword parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by BHG Security Center · textwebappsphp
https://www.exploit-db.com/exploits/18045

This is a writeup detailing multiple vulnerabilities in PHP Photo Album <= 0.4.1.16, including XSS, local file disclosure, and PHP code injection. It provides proof-of-concept URLs but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Xss | Info Leak | Other
Complexity
Trivial
Reliability
Reliable
Target: PHP Photo Album <= 0.4.1.16
No auth needed
Prerequisites: Access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18045

Scores

EPSS 0.0134
EPSS Percentile 67.6%

Details

CWE
CWE-79
Status published
Products (11)
phpalbum/phpalbum 0.2.1
phpalbum/phpalbum 0.2.2
phpalbum/phpalbum 0.2.3
phpalbum/phpalbum 0.2.4
phpalbum/phpalbum 0.3.0
phpalbum/phpalbum 0.3.1 (3 CPE variants)
phpalbum/phpalbum 0.3.2
phpalbum/phpalbum 0.4.1-14 (6 CPE variants)
phpalbum/phpalbum 0.4.1.14
phpalbum/phpalbum 0.4.1.15
... and 1 more
Published Dec 14, 2011
Tracked Since Feb 18, 2026