VYPR
Medium severity6.1NVD Advisory· Published Aug 31, 2017· Updated Jun 17, 2026

CVE-2016-10508

CVE-2016-10508

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in demo/phpThumb.demo.showpic.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:phpthumb_project:phpthumb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phpthumb_project:phpthumb:*:*:*:*:*:*:*:*range: <=1.7.13
    • (no CPE)range: <1.7.14

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.