CVE Vulnerabilities

CVE-2002-1334

Published: Dec 11, 2002 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

Affected Software

Name Vendor Start Version End Version
Imagefolio Bizdesign 2.23 (including) 2.23 (including)
Imagefolio Bizdesign 2.24 (including) 2.24 (including)
Imagefolio Bizdesign 2.26 (including) 2.26 (including)
Imagefolio Bizdesign 2.27 (including) 2.27 (including)
Imagefolio Bizdesign 3.0.1 (including) 3.0.1 (including)

References