PT-2006-1170 · Unknown · Next Generation Image Gallery
Publicado
2006-01-05
·
Atualizado
2011-03-08
·
CVE-2006-0086
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Next Generation Image Gallery version 0.0.1 Lite Edition
Description:
The issue allows remote attackers to inject arbitrary web script or HTML via the
page parameter in the "index.php" file. This can lead to cross-site scripting.Recommendations:
For Next Generation Image Gallery version 0.0.1 Lite Edition, avoid using the
page parameter in the index.php file until a fix is available. As a temporary workaround, consider validating and sanitizing user input for the page parameter to prevent malicious script injection.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Next Generation Image Gallery