Vulnerabilities > CVE-2007-2098 - Cross-Site Scripting vulnerability in Wabbit PHP Gallery 0.9

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
wabbit
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) pic and (2) gal parameters.

Vulnerable Configurations

Part Description Count
Application
Wabbit
1

Exploit-Db

descriptionWabbit Gallery Script 0.9 Showpic.PHP Multiple Cross-Site Scripting Vulnerabilities. CVE-2007-2098. Webapps exploit for php platform
idEDB-ID:29865
last seen2016-02-03
modified2007-04-17
published2007-04-17
reporterthe_Edit0r
sourcehttps://www.exploit-db.com/download/29865/
titleWabbit Gallery Script 0.9 Showpic.PHP Multiple Cross-Site Scripting Vulnerabilities