5
CVSSv2

CVE-2007-1102

Published: 26/02/2007 Updated: 16/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Photostand 1.2.0 allows remote malicious users to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.

Vulnerable Product Search on Vulmon Subscribe to Product

photostand photostand 1.2.0