PT-2010-2702 · Obsession Design · Obsession-Design Image-Gallery

Publicado

2010-03-16

·

Atualizado

2010-03-17

·

CVE-2010-0979

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Obsession-Design Image-Gallery (ODIG) version 1.1
Description The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the folder parameter in the display.php file.
Recommendations For Obsession-Design Image-Gallery (ODIG) version 1.1, consider restricting access to the display.php file until a patch is available, and avoid using the folder parameter in this file to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0979

Produtos afetados

Obsession-Design Image-Gallery