CVE-2017-16356
MEDIUMSimple Image Gallery Extended < 3.3.0 - Reflected Cross-Site Scripting via img, name, or caption Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16356. PoCs published by Alwin Peppels.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Joomla! Component SIGE versions <= 3.2.3 via the 'caption' parameter in 'print.php'. The PoC injects JavaScript through an unsanitized URL parameter, triggering an alert popup.
Description
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Joomla! Component SIGE versions <= 3.2.3 via the 'caption' parameter in 'print.php'. The PoC injects JavaScript through an unsanitized URL parameter, triggering an alert popup.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N