Description
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) collections.php, (3) groups.php, or (4) videos.php; (5) query parameter to search_result.php; or (6) type parameter to view_collection.php or (7) view_item.php.
Exploits (8)
exploitdb
WORKING POC
VERIFIED
by YaDoY666 · textwebappsphp
https://www.exploit-db.com/exploits/36528
exploitdb
WORKING POC
VERIFIED
by YaDoY666 · textwebappsphp
https://www.exploit-db.com/exploits/36527
exploitdb
WORKING POC
VERIFIED
by YaDoY666 · textwebappsphp
https://www.exploit-db.com/exploits/36526
exploitdb
WORKING POC
VERIFIED
by YaDoY666 · textwebappsphp
https://www.exploit-db.com/exploits/36525
exploitdb
WORKING POC
VERIFIED
by YaDoY666 · textwebappsphp
https://www.exploit-db.com/exploits/36524
References (13)
Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78195
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51321
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78194
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78199
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.org/files/108489/clipbucket-sqlxss.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78196
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/18341
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78197
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72245
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78193
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78198
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/47474
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/78200
Scores
EPSS
0.1232
EPSS Percentile
93.9%
Details
CWE
CWE-79
Status
published
Products (1)
clip-bucket/clipbucket
2.6
Published
Apr 08, 2014
Tracked Since
Feb 18, 2026