Bug: XSS flaw in MG2 Image Gallery (v.0.5.1) (WLB-2006010075 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: XSS flaw in MG2 Image Gallery (v.0.5.1)
 Credit: Preben Nyloekken
 Date: 2006.01.30
 CWE: CWE-79 (Show similar)
 CVE: CVE-2006-0493 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
Yes
Yes

Users can inject XSS into the form field "Name", when adding a comment on a picture. This will lead to the
execution of XSS code.

Simple scripting like <script>alert('hello')</script> , and more advanced document.location, and
document.cookie works.

This has been tested on version 0.5.1. Other versions might be flawed too.

Please credit to: Preben Nyl?kken

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com