Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-1985Cross-site Scripting in Photo Gallery

11 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 30
Latest updateApr 29

Description

Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-fwr5-2f5h-8j4r: Cross-site scripting (XSS) vulnerability in menu2022-04-29
CVEList
CVE-2004-1985: Cross-site scripting (XSS) vulnerability in menu2005-05-10

💥Exploits & PoCs

8
Exploit-DB
Ipswitch WS_FTP Server 5.03 - MKD Remote Buffer Overflow2004-11-29
Exploit-DB
MiniShare 1.4.1 - Remote Buffer Overflow (2)2004-11-16
Exploit-DB
TABS MailCarrier 2.51 - Remote Buffer Overflow2004-11-16
Exploit-DB
Ability Server 2.34 (Unix) - FTP 'STOR' Remote Buffer Overflow2004-11-07
Exploit-DB
TABS MailCarrier 2.51 - SMTP 'EHLO' / 'HELO' Remote Buffer Overflow2004-10-26