CVE-2006-3036
Summary
| CVE | CVE-2006-3036 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-15 10:02:00 UTC |
| Updated | 2018-10-18 16:45:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Andy Mack | 35mmslidegallery | 6.0 | All | All | All |
| Application | Andy Mack | 35mmslidegallery | 6.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 26507 | OSVDB | www.osvdb.org | |
| Secunia - Advisories - 35mm Slide Gallery Multiple Cross-Site Scripting Vulnerabilities | SECUNIA | secunia.com | Vendor Advisory |
| SecurityReason - multiple Xss exploits in 35mmslidegallery V6 | SREASON | securityreason.com | |
| 35mmslidegallery Multiple Cross-Site Scripting Vulnerabilities | BID | www.securityfocus.com | Exploit |
| 26508 | OSVDB | www.osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.