CVE-2012-1211

Powie Pfile - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in Powie pFile 1.02 allows remote attackers to inject arbitrary web script or HTML via the filecat parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by indoushka · textwebappsphp
https://www.exploit-db.com/exploits/36765

Scores

EPSS 0.0152
EPSS Percentile 81.0%

Classification

CWE
CWE-79
Status published

Affected Products (2)

powie/pfile
n/a/n/a

Timeline

Published Feb 24, 2012
Tracked Since Feb 18, 2026