CVE-2012-0995 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php (2) PATH_INTO to an unspecified URL as demonstrated using /1/ (3) PATH_INFO to zp-core/admin.php or (4) album parameter to zp-core/admin-edit.php.
Reference
http://archives.neohapsis.com/archives/bugtraq/2012-02/0037.html http://secunia.com/advisories/47875 http://www.securityfocus.com/bid/51916 http://www.zenphoto.org/news/zenphoto-1.4.2.1 http://www.zenphoto.org/trac/changeset/8994 http://www.zenphoto.org/trac/changeset/8995 https://exchange.xforce.ibmcloud.com/vulnerabilities/73083 https://www.htbridge.ch/advisory/HTB23070
Share on: