Description
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (9)
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44433
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/30546
Exploit x_refsource_misc
http://www.securityfocus.com/bid/30546/exploit
Scores
EPSS
0.0020
EPSS Percentile
41.7%
Details
CWE
CWE-79
Status
published
Products (2)
softbiz/image_gallery
softbizscripts/image_gallery_script
Published
Aug 07, 2008
Tracked Since
Feb 18, 2026