Vulnerabilities > Softbiz > Image Gallery > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-08-07 CVE-2008-3511 Cross-Site Scripting vulnerability in Softbiz Image Gallery
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/.
network
softbiz CWE-79
4.3
2006-04-07 CVE-2006-1660 Cross-Site Scripting vulnerability in Image Gallery
Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter.
network
softbiz
6.8
2006-04-07 CVE-2006-1659 SQL Injection vulnerability in Softbiz Image Gallery
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php.
network
low complexity
softbiz
6.4