Cross-Site Scripting Vulnerability in Next Generation Image Gallery by NextGen
CVE-2006-0086
Currently unrated
Key Information:
- Vendor
- CVE Published:
- 5 January 2006
What is CVE-2006-0086?
The index.php file in the Next Generation Image Gallery version 0.0.1 Lite Edition contains a cross-site scripting (XSS) vulnerability. This flaw allows remote attackers to inject arbitrary web scripts or HTML into the application via the 'page' parameter. If exploited, this vulnerability can lead to unauthorized actions performed on behalf of the user and the potential for data theft.
