PT-2006-3931 · Clickgallery · Clickgallery

Publicado

2006-06-15

·

Atualizado

2017-07-20

·

CVE-2006-3026

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ClickGallery versions 5.0 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the gallery id parameter in "gallery.asp" and the parentcurrentpage parameter in "view gallery.asp".
Recommendations For ClickGallery versions 5.0 and earlier, consider restricting access to the vulnerable parameters gallery id and parentcurrentpage in the affected API endpoints "gallery.asp" and "view gallery.asp" until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3026

Produtos afetados

Clickgallery