Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-2698 (webalbum)

BugsAlert Home > CVE-2008-2698 (webalbum)
 
 

Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2698

Learn more about CVE-2008-2698 (webalbum)
 
Tags: cve-2008-2698 webalbum

Related Items

      Bugtraq: Re: Re: Re: Re: Opera 9.6x file:// overflow

      Power Audio CD Burner NCTAudioInformation2 ActiveX Control Buffer Overflow

      WORM_SILLYFDC.CS

      LI-countdown SQL Injection Vulnerability

      Vuln: phpMyAdmin Local Information Disclosure Vulnerability

      FrSIRT - TOKOKITA Multiple Parameter Remote SQL Injection Vulnerabilities

      Vuln: HP-UX 'ftpd' Remote Privilege Escalation Vulnerability

 

Pixel