VulnerabilityModified
CVE-2006-2294
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php.
MEDIUM 6.8EPSS 2.14%
Does this matter?
Lower severity and a low EPSS score (2.14%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- timobraun/dynamic galerie
- Source
- cve@mitre.org
References
- http://d4igoro.blogspot.com/2006/05/dynamic-galerie-10-path-traversal-xss.html
- http://secunia.com/advisories/19995Vendor Advisory
- http://www.osvdb.org/25443
- http://www.osvdb.org/25444
- http://www.securityfocus.com/bid/17896
- http://www.vupen.com/english/advisories/2006/1699
- http://d4igoro.blogspot.com/2006/05/dynamic-galerie-10-path-traversal-xss.html
- http://secunia.com/advisories/19995Vendor Advisory
- http://www.osvdb.org/25443
- http://www.osvdb.org/25444
- http://www.securityfocus.com/bid/17896
- http://www.vupen.com/english/advisories/2006/1699
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.