CVE Vulnerabilities

CVE-2006-5598

Published: Oct 28, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.

Affected Software

NameVendorStart VersionEnd Version
Goop_galleryWebgeneius2.0 (including)2.0 (including)
Goop_galleryWebgeneius2.0.1 (including)2.0.1 (including)
Goop_galleryWebgeneius2.0.2 (including)2.0.2 (including)

References