6.1
CVSSv3

CVE-2018-5705

Published: 24/01/2018 Updated: 09/02/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for malicious users to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.

Vulnerable Product Search on Vulmon Subscribe to Product

reservo image hosting 1.6

Exploits

# Exploit Title: Reservo Image Hosting Script 15 - Cross Site Scripting # Date: 15-01-2018 # Exploit Author: Dennis Veninga # Contact Author: dveninga [at] networking4allcom # Vendor Homepage: reservoco # Version: 16 # CVE-ID: CVE-2018-5705 With support for automatic thumbnails & image resizing in over 200 image formats, robust privacy op ...
Reservo Image Hosting Script version 15 suffers from a cross site scripting vulnerability ...