CVE-2012-0995
ZENphoto 1.4.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH_INFO to zp-core/admin.php, or (4) album parameter to zp-core/admin-edit.php.
References (8)
Scores
EPSS
0.0054
EPSS Percentile
67.5%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
zenphoto/zenphoto
n/a/n/a
Timeline
Published
Feb 21, 2012
Tracked Since
Feb 18, 2026