RSS   Vulnerabilities for 'Idms pro image gallery'   RSS

2006-11-30
 
CVE-2006-6196

CWE-Other
 

 
Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter).

 
 
CVE-2006-6195

CWE-Other
 

 
Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.

 


Copyright 2024, cxsecurity.com

 

Back to Top