Description
|
|
Multiple vulnerabilities were identified in My Image Gallery, which may be exploited by attackers to inject malicious HTML code. This flaw is due to input validation errors in the "index.php" script that does not properly filter specially crafted "currDir" and "image" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser. The second issue is due to an input validation error in "index.php" script when processing an invalid "image" variable, which could be exploited to display the installation path.
|