← Back

CVE-2011-4806

nvd nist
Published: Dec 14, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in main.php in phpAlbum 0.4.1.16 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) var1 and (2) keyword parameters.

Affected (18)

Products: Phpalbum: Phpalbum
1 product
Phpalbum
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Phpalbum
Up to 0.4.1.16
Version 0.2.1
Version 0.2.2
Version 0.2.3
Version 0.2.4
Version 0.3.0
Version 0.3.1
Version 0.3.1 fix01
Version 0.3.1 fix02
Version 0.3.2
Version 0.4.1-14
Version 0.4.1-14 fix01
Version 0.4.1-14 fix02
Version 0.4.1-14 fix03
Version 0.4.1-14 fix05
Version 0.4.1-14 fix06
Version 0.4.1.14
Version 0.4.1.15

References (2)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.