CVE-2004-2245 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 81)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 2.04% — more likely to be exploited than 81% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| goollery | goollery |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Goolery 0.3 - 'viewalbum.php?page' Cross-Site Scripting | 2004-11-02 |
References
- http://securitytracker.com/id?1012062
- http://www.osvdb.org/11318
- http://www.osvdb.org/11319
- http://www.osvdb.org/11320
- http://www.osvdb.org/ref/11/11xxx-goollery_multiple.txt
- http://www.securityfocus.com/bid/11587
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17957
- http://securitytracker.com/id?1012062
- http://www.osvdb.org/11318
- http://www.osvdb.org/11319
- http://www.osvdb.org/11320
- http://www.osvdb.org/ref/11/11xxx-goollery_multiple.txt
- http://www.securityfocus.com/bid/11587
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17957
→ the Explorer · watch your stack · NVD