Family: CGI abuses : XSS --> Category: infos
Goollery Multiple XSS Vulnerability Scan
Vulnerability Scan Summary
Searches for the existence of Goollery XSS flaw in viewpic.php
Detailed Explanation for this Vulnerability Test
Goollery, a GMail based photo gallery written in PHP,
is installed on this remote host.
According to it's version number, this host is vulnerable to multiple
cross-site-scripting (XSS) attacks
eg, through the 'viewpic.php'
script. A possible hacker, exploiting these flaws, would need to be able to
coerce a user to browse a malicious URI. Upon successful exploitation,
the attacker would be able to run code within the web-browser in the
security context of the remote server.
Solution : Upgrade to Goollery 0.04b or newer.
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.