CVE-2015-2275

WoltLab Community Gallery 2.0 - Stored Cross-Site Scripting via Image Title Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-2275. PoCs published by ITAS Team.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Community Gallery 2.0 before 12/10/2014. The PoC shows how an attacker can inject malicious JavaScript into the 'title' parameter, which is then stored and executed when other users view the affected image.

Description

Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy.

Exploits (1)

exploitdb WORKING POC
by ITAS Team · textwebappsphp
https://www.exploit-db.com/exploits/36368

This exploit demonstrates a stored XSS vulnerability in Community Gallery 2.0 before 12/10/2014. The PoC shows how an attacker can inject malicious JavaScript into the 'title' parameter, which is then stored and executed when other users view the affected image.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Community Gallery 2.0 before 12/10/2014
Auth required
Prerequisites: Access to a valid session cookie · Ability to send HTTP POST requests to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Mar/65
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/119455
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73053
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534841/100/0/threaded
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36368

Scores

EPSS 0.0372
EPSS Percentile 88.4%

Details

CWE
CWE-79
Status published
Products (1)
wotlab/community_gallery 2.0
Published Mar 12, 2015
Tracked Since Feb 18, 2026