5.8
CVE-2006-2052
- EPSS 1.82%
- Veröffentlicht 26.04.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:24:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Verosky Media ≫ Instant Photo Gallery Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.82% | 0.76 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://securityreason.com/securityalert/790
http://www.osvdb.org/24984
http://www.securityfocus.com/archive/1/432022/100/0/threaded
http://www.securityfocus.com/archive/1/432241/100/0/threaded
http://www.securityfocus.com/bid/17696