CVE Vulnerabilities

CVE-2002-1334

Published: Dec 11, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

Affected Software

NameVendorStart VersionEnd Version
ImagefolioBizdesign2.23 (including)2.23 (including)
ImagefolioBizdesign2.24 (including)2.24 (including)
ImagefolioBizdesign2.26 (including)2.26 (including)
ImagefolioBizdesign2.27 (including)2.27 (including)
ImagefolioBizdesign3.0.1 (including)3.0.1 (including)

References