VendorsBizdesignimagefolio2.27
Vulnerabilities

Bizdesign Imagefolio 2.27

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2002-1334
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.
Published 2002-12-03 · Modified
6.82 PoCEPSS 0.047
CVE-2002-1801
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
Published 2005-06-28 · Modified
5.0EPSS 0.018