Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Bizdesign Subscribe
Filtered by product Imagefolio
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1334 1 Bizdesign 1 Imagefolio 2017-07-10 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.
CVE-2002-1867 1 Bizdesign 1 Imagefolio 2016-10-17 7.5 HIGH N/A
The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).
CVE-2002-1801 1 Bizdesign 1 Imagefolio 2008-09-05 5.0 MEDIUM N/A
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.