Vulnerability Details CVE-2016-10508
Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in demo/phpThumb.demo.showpic.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2016-10508
-
cpe:2.3:a:phpthumb_project:phpthumb:1.7.11
-
cpe:2.3:a:phpthumb_project:phpthumb:1.7.12
-
cpe:2.3:a:phpthumb_project:phpthumb:1.7.13