Vulnerabilities > CVE-2006-4259 - Cross-Site Scripting vulnerability in Jake Olefsky Fotopholder 1.8

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
jake-olefsky

Summary

Cross-site scripting (XSS) vulnerability in index.php in Fotopholder 1.8 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this might be resultant from a directory traversal vulnerability.

Vulnerable Configurations

Part Description Count
Application
Jake_Olefsky
1