PT-2006-1170 · Unknown · Next Generation Image Gallery

Publicado

2006-01-05

·

Atualizado

2011-03-08

·

CVE-2006-0086

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Next Generation Image Gallery version 0.0.1 Lite Edition
Description: The issue allows remote attackers to inject arbitrary web script or HTML via the page parameter in the "index.php" file. This can lead to cross-site scripting.
Recommendations: For Next Generation Image Gallery version 0.0.1 Lite Edition, avoid using the page parameter in the index.php file until a fix is available. As a temporary workaround, consider validating and sanitizing user input for the page parameter to prevent malicious script injection.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0086

Produtos afetados

Next Generation Image Gallery