CVE-2011-1063

Cherry-software Photopad - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cherry-Design Photopad 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) data[title] parameters in an edit action to files.php, or (3) id parameter in a view action to gallery.php.

Scores

EPSS 0.0040
EPSS Percentile 60.4%

Classification

CWE
CWE-79
Status published

Affected Products (2)

cherry-software/photopad
n/a/n/a

Timeline

Published Feb 23, 2011
Tracked Since Feb 18, 2026