CVE Vulnerabilities

CVE-2002-1334

Published: Dec 11, 2002 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

Affected Software

Name Vendor Start Version End Version
Imagefolio Bizdesign 2.23 (including) 2.23 (including)
Imagefolio Bizdesign 2.24 (including) 2.24 (including)
Imagefolio Bizdesign 2.26 (including) 2.26 (including)
Imagefolio Bizdesign 2.27 (including) 2.27 (including)
Imagefolio Bizdesign 3.0.1 (including) 3.0.1 (including)

References