Vulnerabilities > CVE-2007-2806 - Cross-Site Scripting vulnerability in Galix 2.0

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
galix
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters.

Vulnerable Configurations

Part Description Count
Application
Galix
1

Exploit-Db

descriptionGaliX 2.0 Index.PHP Multiple Cross Site Scripting Vulnerabilities. CVE-2007-2806. Webapps exploit for php platform
idEDB-ID:30065
last seen2016-02-03
modified2007-05-21
published2007-05-21
reporterJohn Martinelli
sourcehttps://www.exploit-db.com/download/30065/
titleGaliX 2.0 Index.PHP Multiple Cross-Site Scripting Vulnerabilities