Intrusion Prevention

Absolute.Image.Gallery.XE.XSS

Description

It indicates a possible exploit of a cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE.
This flaw is due to an input validation error in the "gallery.asp" script that does not validate the "shownew" parameter, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.

Affected Products

Absolute Image Gallery XE version 2.0 and prior

Impact

The injection arbitrary web script or HTML on the system.

Recommended Actions

Upgrade to the latest version of the vulnerable software.

CVE References

CVE-2006-1411