CVE-2006-5057

Ktools.net PhotoStore - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by meto5757 · textwebappsphp
https://www.exploit-db.com/exploits/28663
exploitdb WRITEUP VERIFIED
by meto5757 · textwebappsphp
https://www.exploit-db.com/exploits/28662

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1640
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22122
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20172
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3781
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/446909/100/0/threaded

Scores

EPSS 0.0319
EPSS Percentile 87.0%

Details

Status published
Products (1)
ktools.net/photostore
Published Sep 28, 2006
Tracked Since Feb 18, 2026