Bizdesign Imagefolio vulnerabilities
3 known vulnerabilities affecting bizdesign/imagefolio.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2002-1334P4MEDIUMCVSS 6.8PoCv2.23v2.24+3 more2002-12-11
CVE-2002-1334 [MEDIUM] CVE-2002-1334: Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote atta
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.
nvd
CVE-2002-1867P4HIGHCVSS 7.5v2.23v2.24+1 more2002-12-31
CVE-2002-1867 [HIGH] CVE-2002-1867: The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) a
The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).
nvd
CVE-2002-1801P4MEDIUMCVSS 5.0v2.23v2.24+2 more2002-12-31
CVE-2002-1801 [MEDIUM] CVE-2002-1801: ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexiste
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
nvd