Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zenphoto | Zenphoto | * | 1.0.1_beta (including) |
Zenphoto | Zenphoto | 0.9 (including) | 0.9 (including) |
Zenphoto | Zenphoto | 1.0_beta (including) | 1.0_beta (including) |