PT-2006-3937 · Xtreme · Xtreme Asp Photo Gallery
Published
2006-06-15
·
Updated
2017-07-20
·
CVE-2006-3032
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Xtreme ASP Photo Gallery versions 1.05 and earlier
Xtreme ASP Photo Gallery version 2.0 (trial)
Description
The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters in certain ASP files. The vulnerable parameters are
catname and total in "displaypic.asp", and catname in "displaythumbs.asp".Recommendations
For Xtreme ASP Photo Gallery versions 1.05 and earlier, consider restricting access to the "displaypic.asp" and "displaythumbs.asp" files until a patch is available.
For Xtreme ASP Photo Gallery version 2.0 (trial), avoid using the
catname and total parameters in the affected API endpoints until the issue is resolved.
As a temporary workaround, consider validating and sanitizing user input for the catname and total parameters to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xtreme Asp Photo Gallery