Vulnerabilities > CVE-2007-2806 - Cross-Site Scripting vulnerability in Galix 2.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | GaliX 2.0 Index.PHP Multiple Cross Site Scripting Vulnerabilities. CVE-2007-2806. Webapps exploit for php platform |
id | EDB-ID:30065 |
last seen | 2016-02-03 |
modified | 2007-05-21 |
published | 2007-05-21 |
reporter | John Martinelli |
source | https://www.exploit-db.com/download/30065/ |
title | GaliX 2.0 Index.PHP Multiple Cross-Site Scripting Vulnerabilities |