Advertisement






AZ Photo Album Script Pro

CVE Category Price Severity
CVE-XXXX-XXXX CWE-XX Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2006-06-06
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006050186

Below is a copy:

AZ Photo Album Script Pro

Homepage:

http://www.php4script.com/php-photo-album-script/

Description:

A powerful PHP/MySQL photo album (photo gallery) script with a lot of features.

Effected files:

index.php

Exploits & Vulns:

Captivate is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the

attacker steal cookie-based authentication credentials and launch other attacks.

Proof of Concept:

http://www.example.com/index.php?&gazpart=view<IMG%20"""><SCRIPT>alert("
XSS")</SCRIPT>">&<IMG%20"""><SCRIPT>alert("XSS")</SCRIPT>">gazimage=198

I couldn't find a version # on the homepage for this script.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum