Vulnerabilities > CVE-2006-2955 - Unspecified vulnerability in Kaphotoservice
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN kaphotoservice
exploit available
Summary
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b) album.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description KAPhotoservice 7.5 album.asp cat Parameter XSS. CVE-2006-2955 . Webapps exploit for asp platform id EDB-ID:28002 last seen 2016-02-03 modified 2006-06-09 published 2006-06-09 reporter r0t source https://www.exploit-db.com/download/28002/ title KAPhotoservice 7.5 album.asp cat Parameter XSS description KAPhotoservice 7.5 edtalbum.asp Multiple Parameter XSS. CVE-2006-2955. Webapps exploit for asp platform id EDB-ID:28004 last seen 2016-02-03 modified 2006-06-09 published 2006-06-09 reporter r0t source https://www.exploit-db.com/download/28004/ title KAPhotoservice 7.5 edtalbum.asp Multiple Parameter XSS description KAPhotoservice 7.5 albums.asp albumid Parameter XSS. CVE-2006-2955 . Webapps exploit for asp platform id EDB-ID:28003 last seen 2016-02-03 modified 2006-06-09 published 2006-06-09 reporter r0t source https://www.exploit-db.com/download/28003/ title KAPhotoservice 7.5 albums.asp albumid Parameter XSS
References
- http://pridels0.blogspot.com/2006/06/kaphotoservice-75-vuln.html
- http://pridels0.blogspot.com/2006/06/kaphotoservice-75-vuln.html
- http://secunia.com/advisories/20521
- http://secunia.com/advisories/20521
- http://securitytracker.com/id?1016253
- http://securitytracker.com/id?1016253
- http://www.osvdb.org/26275
- http://www.osvdb.org/26275
- http://www.osvdb.org/26276
- http://www.osvdb.org/26276
- http://www.securityfocus.com/bid/18379
- http://www.securityfocus.com/bid/18379
- http://www.vupen.com/english/advisories/2006/2251
- http://www.vupen.com/english/advisories/2006/2251
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27073
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27073