Security Advisory

CVE-2007-4259

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-08-08 23:00:00
Last updated 2024-08-07 14:46:39
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

EZPhotoSales 1.9.3 and earlier allows remote attackers to download arbitrary image files via (1) a direct request for a URL under OnlineViewing/galleries/ or (2) navigation of the gallery user interface with JavaScript disabled.