CVE-2006-1826 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php (2) keyword parameter in search.php and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are resultant from SQL injection.
Reference
http://securitytracker.com/id?1015947 http://www.securityfocus.com/archive/1/431074/100/0/threaded http://www.securityfocus.com/archive/1/431123/100/0/threaded http://www.securityfocus.com/bid/17543 https://exchange.xforce.ibmcloud.com/vulnerabilities/25803
Share on: