Vulnerabilities
Vulnerable Software
Bizdesign:  >> Imagefolio  >> 2.23  Security Vulnerabilities
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
CVSS Score
5.0
EPSS Score
0.006
Published
2002-12-31
The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).
CVSS Score
7.5
EPSS Score
0.007
Published
2002-12-31
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.
CVSS Score
6.8
EPSS Score
0.011
Published
2002-12-11


Contact Us

Shodan ® - All rights reserved