| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.15717 |
| Category: | Web application abuses |
| Title: | Goollery Multiple XSS |
| Summary: | Checks for the presence of Goollery XSS flaw in viewpic.php |
| Description: | Goollery, a GMail based photo gallery written in PHP, is installed on this remote host. According to it's version number, this host is vulnerable to multiple cross-site-scripting (XSS) attacks eg, through the 'viewpic.php' script. An attacker, exploiting these flaws, would need to be able to coerce a user to browse a malicious URI. Upon successful exploitation, the attacker would be able to run code within the web-browser in the security context of the remote server. Solution : Upgrade to Goollery 0.04b or newer. |
| Cross-Ref: |
BugTraq ID: 11587 Common Vulnerability Exposure (CVE) ID: CVE-2004-2245 http://www.osvdb.org/ref/11/11xxx-goollery_multiple.txt http://www.securityfocus.com/bid/11587 http://www.osvdb.org/11318 http://www.osvdb.org/11319 http://www.osvdb.org/11320 http://securitytracker.com/id?1012062 XForce ISS Database: goollery-viewalbum-viewpic-xss(17957) http://xforce.iss.net/xforce/xfdb/17957 |
| Copyright | This script is Copyright (C) 2004 David Maciejak |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|