Vulnerabilities > CVE-2006-6517 - Unspecified vulnerability in Kdpics
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN kdpics
exploit available
Summary
Multiple cross-site scripting (XSS) vulnerabilities in KDPics 1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) categories parameter to (a) index.php3 or (b) galeries.inc.php3.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description KDPics 1.11/1.16 index.php3 categories Parameter XSS. CVE-2006-6517. Webapps exploit for php platform id EDB-ID:29254 last seen 2016-02-03 modified 2006-12-09 published 2006-12-09 reporter Mr_KaLiMaN source https://www.exploit-db.com/download/29254/ title KDPics 1.11/1.16 index.php3 categories Parameter XSS description KDPics 1.11/1.16 galeries.inc.php3 categories Parameter XSS. CVE-2006-6517. Webapps exploit for php platform id EDB-ID:29255 last seen 2016-02-03 modified 2006-12-09 published 2006-12-09 reporter Mr_KaLiMaN source https://www.exploit-db.com/download/29255/ title KDPics 1.11/1.16 galeries.inc.php3 categories Parameter XSS description KDPics <= 1.11 (exif.php lib_path) Remote File Include Vulnerability. CVE-2006-6516,CVE-2006-6517. Webapps exploit for php platform file exploits/php/webapps/3263.txt id EDB-ID:3263 last seen 2016-01-31 modified 2007-02-03 platform php port published 2007-02-03 reporter AsTrex source https://www.exploit-db.com/download/3263/ title KDPics <= 1.11 exif.php lib_path Remote File Include Vulnerability type webapps
References
- http://secunia.com/advisories/23313
- http://secunia.com/advisories/23313
- http://www.securityfocus.com/archive/1/453962/100/0/threaded
- http://www.securityfocus.com/archive/1/453962/100/0/threaded
- http://www.securityfocus.com/bid/21515
- http://www.securityfocus.com/bid/21515
- http://www.vupen.com/english/advisories/2006/4930
- http://www.vupen.com/english/advisories/2006/4930