3 results (0.017 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector. • https://www.exploit-db.com/exploits/27729 http://attrition.org/pipermail/vim/2006-April/000716.html http://secunia.com/advisories/19777 http://securityreason.com/securityalert/783 http://www.osvdb.org/24891 http://www.securityfocus.com/archive/1/431853/100/0/threaded http://www.securityfocus.com/bid/17668 http://www.vupen.com/english/advisories/2006/1490 https://exchange.xforce.ibmcloud.com/vulnerabilities/26101 •

CVSS: 5.0EPSS: 2%CPEs: 1EXPL: 3

Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order. • https://www.exploit-db.com/exploits/27724 http://attrition.org/pipermail/vim/2006-April/000716.html http://downloads.securityfocus.com/vulnerabilities/exploits/17649-directory-traversal.exploit http://secunia.com/advisories/19777 http://securityreason.com/securityalert/784 http://www.osvdb.org/24889 http://www.securityfocus.com/archive/1/431716/100/0/threaded http://www.securityfocus.com/bid/17649 http://www.securityfocus.com/bid/17668 http://www.vupen.com/english/advisories/2006/1490 •

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 0

Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message. • http://attrition.org/pipermail/vim/2006-April/000716.html http://secunia.com/advisories/19777 http://securityreason.com/securityalert/784 http://www.osvdb.org/24890 http://www.securityfocus.com/archive/1/431716/100/0/threaded http://www.securityfocus.com/bid/17668 http://www.vupen.com/english/advisories/2006/1490 https://exchange.xforce.ibmcloud.com/vulnerabilities/25990 •