Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Goop_gallery | Webgeneius | 2.0 (including) | 2.0 (including) |
| Goop_gallery | Webgeneius | 2.0.1 (including) | 2.0.1 (including) |
| Goop_gallery | Webgeneius | 2.0.2 (including) | 2.0.2 (including) |