Arbitrary Web Script Execution in BizDesign ImageFolio 3.01 and Earlier

Arbitrary Web Script Execution in BizDesign ImageFolio 3.01 and Earlier

CVE-2002-1334 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

Learn more about our Web App Pen Testing.