Vulnerabilities > Cherry Software
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2011-02-23 | CVE-2011-1063 | Cross-Site Scripting vulnerability in Cherry-Software Photopad 1.2.0 Multiple cross-site scripting (XSS) vulnerabilities in Cherry-Design Photopad 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) data[title] parameters in an edit action to files.php, or (3) id parameter in a view action to gallery.php. | 4.3 |