Heap
01-02-08, 19:09
Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters. NOTE: some of these details are obtained from third party information.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0505)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0505)