Описание
Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.
Ссылки
- Exploit
- Exploit
- PatchURL Repurposed
- Exploit
- Exploit
- PatchURL Repurposed
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:webgeneius:goop_gallery:2.0:*:*:*:*:*:*:*
cpe:2.3:a:webgeneius:goop_gallery:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:webgeneius:goop_gallery:2.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00521
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.
EPSS
Процентиль: 66%
0.00521
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other