Vulnerabilities > CVE-2006-3032 - Unspecified vulnerability in Pensacola web Designs Xtreme ASP Photo Gallery 1.05/2.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://pridels0.blogspot.com/2006/06/xtreme-asp-photo-gallery-xss-vuln.html
- http://pridels0.blogspot.com/2006/06/xtreme-asp-photo-gallery-xss-vuln.html
- http://secunia.com/advisories/20604
- http://secunia.com/advisories/20604
- http://www.osvdb.org/26398
- http://www.osvdb.org/26398
- http://www.osvdb.org/26399
- http://www.osvdb.org/26399
- http://www.vupen.com/english/advisories/2006/2292
- http://www.vupen.com/english/advisories/2006/2292
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27033
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27033