Vulnerabilities > CVE-2006-1660 - Cross-Site Scripting vulnerability in Image Gallery

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
softbiz

Summary

Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. This vulnerability most likely affects all versions of Softbiz, Image Gallery.

Vulnerable Configurations

Part Description Count
Application
Softbiz
1