| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.103104 |
| Category: | Web application abuses |
| Title: | PhotoPost PHP 'showgallery.php' Multiple Cross Site Scripting Vulnerabilities |
| Summary: | Determine if PhotoPost is prone to multiple cross-site scripting vulnerabilities |
| Description: | Overview: PhotoPost PHP is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user- supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. PhotoPost PHP 4.8c is vulnerable other versions may also be affected. References: https://www.securityfocus.com/bid/46649 http://www.photopost.com http://www.securityfocus.com/archive/1/516793 |
| Cross-Ref: |
BugTraq ID: 46649 Common Vulnerability Exposure (CVE) ID: CVE-2005-0274 Bugtraq: 20050103 Multiple PhotoPost Pro Vulnerabilities (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=110486165802196&w=2 http://www.gulftech.org/?node=research&article_id=00063-01032005 BugTraq ID: 12156 http://www.securityfocus.com/bid/12156 http://secunia.com/advisories/13680/ XForce ISS Database: photopost-php-showgallery-xss(18744) http://xforce.iss.net/xforce/xfdb/18744 |
| Copyright | This script is Copyright (C) 2011 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|