Vulnerabilities > CVE-2006-0927 - Cross-Site Scripting vulnerability in JGS-Gallery Module

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
jgs-xa
woltlab
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php. Vulnerability affects JGS-XA, JGS-Gallery Addon versions 4.0.0 and previous.

Exploit-Db

  • descriptionJGS-Gallery 4.0 jgs_galerie_slideshow.php Multiple Parameter XSS. CVE-2006-0927. Webapps exploit for php platform
    idEDB-ID:27306
    last seen2016-02-03
    modified2006-02-23
    published2006-02-23
    reporternuker
    sourcehttps://www.exploit-db.com/download/27306/
    titleJGS-Gallery 4.0 jgs_galerie_slideshow.php Multiple Parameter XSS
  • descriptionJGS-Gallery 4.0 Board jgs_galerie_scroll.php userid Parameter XSS. CVE-2006-0927. Webapps exploit for php platform
    idEDB-ID:27307
    last seen2016-02-03
    modified2006-02-23
    published2006-02-23
    reporternuker
    sourcehttps://www.exploit-db.com/download/27307/
    titleJGS-Gallery 4.0 Board jgs_galerie_scroll.php userid Parameter XSS