Unrated severityNVD Advisory· Published Feb 21, 2012· Updated Apr 29, 2026
CVE-2012-0995
CVE-2012-0995
Description
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH_INFO to zp-core/admin.php, or (4) album parameter to zp-core/admin-edit.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- archives.neohapsis.com/archives/bugtraq/2012-02/0037.htmlnvdExploit
- www.securityfocus.com/bid/51916nvdExploit
- www.zenphoto.org/trac/changeset/8994nvdExploitPatch
- www.zenphoto.org/trac/changeset/8995nvdExploitPatch
- www.htbridge.ch/advisory/HTB23070nvdExploit
- secunia.com/advisories/47875nvdVendor Advisory
- www.zenphoto.org/news/zenphoto-1.4.2.1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/73083nvd
News mentions
0No linked articles in our index yet.