vendor:
IP.Gallery
by:
Mohamed Ramadan
8,8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: IP.Gallery
Affected Version From: 4.2.x
Affected Version To: 5.0.x
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
IP.Gallery 4.2.x and 5.0.x persistent XSS vulnerability
image title is vulnerable to persistent XSS vulnerability which allow any normal member to hack any administrator account or any other member account.
Mitigation:
The vendor released a patch to fix the vulnerability: http://community.invisionpower.com/topic/379028-ipgallery-42x-and-50x-security-update/