Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-5593

The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>payload<script></script></script>", or in an image tag, with the payload as the onerror event.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2015-5593


Contact Us

Shodan ® - All rights reserved