Lucene search

K

Imagefolio Security Vulnerabilities

cve
cve

CVE-2002-1334

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

6.3AI Score

0.01EPSS

2002-12-11 05:00 AM
42
cve
cve

CVE-2002-1801

ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.

6.5AI Score

0.004EPSS

2005-06-28 04:00 AM
23
cve
cve

CVE-2002-1867

The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).

7.1AI Score

0.01EPSS

2005-06-28 04:00 AM
23