CVE-2011-4806
14.12.2011, 00:55
Multiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) var1 and (2) keyword parameters.
Vendor | Product | Version |
---|---|---|
phpalbum | phpalbum | 𝑥 ≤ 0.4.1.16 |
phpalbum | phpalbum | 0.2.1 |
phpalbum | phpalbum | 0.2.2 |
phpalbum | phpalbum | 0.2.3 |
phpalbum | phpalbum | 0.2.4 |
phpalbum | phpalbum | 0.3.0 |
phpalbum | phpalbum | 0.3.1 |
phpalbum | phpalbum | 0.3.1:fix01 |
phpalbum | phpalbum | 0.3.1:fix02 |
phpalbum | phpalbum | 0.3.2 |
phpalbum | phpalbum | 0.4.1-14 |
phpalbum | phpalbum | 0.4.1-14:fix01 |
phpalbum | phpalbum | 0.4.1-14:fix02 |
phpalbum | phpalbum | 0.4.1-14:fix03 |
phpalbum | phpalbum | 0.4.1-14:fix05 |
phpalbum | phpalbum | 0.4.1-14:fix06 |
phpalbum | phpalbum | 0.4.1.14 |
phpalbum | phpalbum | 0.4.1.15 |
𝑥
= Vulnerable software versions