Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Al7Ejaz Hackerz

#21010of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2006-6754
6.8
2006-11-26
Mmgallery · Mmgallery · CVE-2006-6118
**Name of the Vulnerable Software and Affected Versions** mmgallery version 1.55 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `page` parameter in the thumbs.php file. **Recommendations** For mmgallery version 1.55, consider restricting access to the thumbs.php file until a patch is available, and avoid using the `page` parameter in this file to minimize the risk of exploitation.
PT-2006-6755
5.0
2006-11-26
Mmgallery · Mmgallery · CVE-2006-6119
**Name of the Vulnerable Software and Affected Versions** mmgallery version 1.55 **Description** The issue allows remote attackers to obtain sensitive information via a direct request for "thumbs.php", which reveals the installation path in various error messages. **Recommendations** For mmgallery version 1.55, consider restricting access to the "thumbs.php" file until a patch is available.