CVE-2008-3511 details multiple cross-site scripting (XSS) vulnerabilities affecting Softbiz Image Gallery (Photo Gallery). These flaws allow remote attackers to inject arbitrary web script or HTML via various parameters in several PHP files, including both public-facing and administrative interfaces. Rated with a CVSS v2 score of 4.3 (Medium), the vulnerabilities require no authentication and have a medium attack complexity, potentially leading to partial integrity impact. While not listed on the CISA KEV catalog or Hot List, several specific proof-of-concept exploits are publicly available on ExploitDB. However, community discussion, media coverage, and EPSS scores indicate very low public attention and exploitation likelihood for this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:softbizscripts:image_gallery_script:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.