First published: Mon Jun 19 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m parameter in (a) common/galleries.asp; (6) aid, (7) aname, (8) uid, (9) m, (10) gp, and (11) g parameter in (b) common/pupload.asp; and (12) msg, (13) fn and (14) gp parameter in (c) common/upload.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Allegro | <=1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3087 is considered a high severity vulnerability due to its potential for allowing cross-site scripting attacks.
To fix CVE-2006-3087, upgrade to a later version of EZGallery that is not affected by this vulnerability.
CVE-2006-3087 can lead to unauthorized access to user data and compromise the integrity of user sessions through XSS attacks.
EZGallery versions 1.5 and earlier are affected by CVE-2006-3087.
Yes, there are potential exploits available for CVE-2006-3087 that can be used by attackers to inject malicious scripts.