Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Al7Ejaz Hackerz

#21010de 53,635
11.8CVSS total
Vulnerabilidades · 2
Média
2
PT-2006-6754
6.8
2006-11-26
Mmgallery · Mmgallery · CVE-2006-6118
**Name of the Vulnerable Software and Affected Versions** mmgallery version 1.55 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `page` parameter in the thumbs.php file. **Recommendations** For mmgallery version 1.55, consider restricting access to the thumbs.php file until a patch is available, and avoid using the `page` parameter in this file to minimize the risk of exploitation.
PT-2006-6755
5.0
2006-11-26
Mmgallery · Mmgallery · CVE-2006-6119
**Name of the Vulnerable Software and Affected Versions** mmgallery version 1.55 **Description** The issue allows remote attackers to obtain sensitive information via a direct request for "thumbs.php", which reveals the installation path in various error messages. **Recommendations** For mmgallery version 1.55, consider restricting access to the "thumbs.php" file until a patch is available.