Vulnerabilities > Bizdesign > Imagefolio > 2.27

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-1801 Unspecified vulnerability in Bizdesign Imagefolio
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
network
low complexity
bizdesign
5.0
2002-12-11 CVE-2002-1334 Cross-Site Scripting vulnerability in BizDesign ImageFolio
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.
network
bizdesign
6.8