Cross-Site Scripting Vulnerabilities in TinyWebGallery by TinyWebGallery
CVE-2007-4958
Currently unrated
What is CVE-2007-4958?
Multiple cross-site scripting vulnerabilities exist in TinyWebGallery version 1.6.3.4, allowing remote attackers to inject arbitrary web scripts or HTML through specific URIs. The vulnerable endpoints include index.php, i_frames/i_login.php, and i_frames/i_top_tags.php, which could lead to unauthorized actions and data exposure for users accessing these scripts.
