Absolute.Image.Gallery.XE.XSS

description-logoDescription

It indicates a possible exploit of a cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE.
This flaw is due to an input validation error in the "gallery.asp" script that does not validate the "shownew" parameter, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.

affected-products-logoAffected Products

Absolute Image Gallery XE version 2.0 and prior

Impact logoImpact

The injection arbitrary web script or HTML on the system.

recomended-action-logoRecommended Actions

Upgrade to the latest version of the vulnerable software.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-12-11 16.978