Vulnerabilities > CVE-2007-2310 - Cross-Site Scripting vulnerability in Bloofoxcms 0.2.2

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
bloofoxcms
exploit available

Summary

Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.

Vulnerable Configurations

Part Description Count
Application
Bloofoxcms
1

Exploit-Db

descriptionBloofoxCMS 0.2.2 Img_Popup.PHP Cross-Site Scripting Vulnerability. CVE-2007-2310. Webapps exploit for php platform
idEDB-ID:29854
last seen2016-02-03
modified2007-04-14
published2007-04-14
reporterthe_Edit0r
sourcehttps://www.exploit-db.com/download/29854/
titleBloofoxCMS 0.2.2 Img_Popup.PHP Cross-Site Scripting Vulnerability