First published: Thu Jun 15 2006(Updated: )
Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fipsasp Fipsgallery | <=1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3022 is categorized as a moderate severity cross-site scripting vulnerability.
To fix CVE-2006-3022, users should upgrade to a version of fipsGallery later than 1.5 that does not contain this vulnerability.
CVE-2006-3022 affects fipsGallery versions 1.5 and earlier.
CVE-2006-3022 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.
While CVE-2006-3022 is from 2006, it remains relevant for systems still running affected versions of fipsGallery.