Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Goollery | Goollery | 0.3 (including) | 0.3 (including) |