ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities

ClickGallery Server is prone to multiple input-validation vulnerabilities, including an SQL-injection issue and a cross-site scripting issue, because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

ClickGallery Server 5.1 and prior versions are vulnerable.


 

Privacy Statement
Copyright 2010, SecurityFocus