vendor:
EasyGallery
by:
JosS
7.5
CVSS
HIGH
Multiple Remote Vulnerabilities
89, 79, 80
CWE
Product Name: EasyGallery
Affected Version From: 5.0tr
Affected Version To: 5.0tr
Patch Exists: NO
Related CWE: N/A
CPE: a:myiosoft:easygallery
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
EasyGallery <= 5.0tr - Multiple Remote Vulnerabilities
EasyGallery 5.0tr is vulnerable to multiple remote vulnerabilities including SQL Injection, Cross Site Scripting in URI and Cross Site Scripting. An attacker can exploit these vulnerabilities to gain unauthorized access to the application and execute malicious code.
Mitigation:
Ensure that user input is validated and filtered properly. Use parameterized queries to prevent SQL Injection. Use a web application firewall to detect and block malicious requests.