6.8
CVSSv2

CVE-2006-6936

Published: 17/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote malicious users to inject arbitrary HTML or web script via (1) the catname parameter to displaypic.asp or (2) the search field. NOTE: vector 1 likely overlaps CVE-2006-3032.

Vulnerable Product Search on Vulmon Subscribe to Product

pensacola web designs xtremeasp photogallery 2.0

Exploits

source: wwwsecurityfocuscom/bid/21138/info Xtreme ASP Photo Gallery is prone to multiple input-validation vulnerabilities, including cross-site scripting and SQL-injection issues and an HTML-injection issue because the application fails to properly sanitize user-supplied input Successful exploits of these vulnerabilities could allow ...