Record summary

CVE-2017-16356 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBJoomla! Component Kubik-Rubik Simple Image Gallery Extended (SIGE) 3.2.3 - Cross-Site ScriptingExploitDB exploitby Alwin PeppelsNot analyzed1 file
ExploitDB

PoC details

References

3