Vulnerabilities > CVE-2006-1996 - Cross-Site Scripting vulnerability in Scry Gallery Scry Gallery 1.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
scry-gallery

Summary

Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message.

Vulnerable Configurations

Part Description Count
Application
Scry_Gallery
1