First published: Fri Apr 24 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the selitems[] parameter in a (1) copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TinyWebGallery Wordpress Flash Uploader | <=1.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2932 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
To mitigate CVE-2012-2932, upgrade TinyWebGallery to version 1.8.8 or later.
CVE-2012-2932 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
CVE-2012-2932 affects TinyWebGallery versions prior to 1.8.8.
The patch for CVE-2012-2932 is included in the release of TinyWebGallery version 1.8.8.