peter bassill · operator
$ cve CVE-2006-2680 JSON

CVE-2006-2680 EXPLOIT

5.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.

Scoring

CVSS5.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS1.88% — more likely to be exploited than 79% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-31
Last modified2026-06-16

Affected (1)

VendorProduct
php4scriptaz photo album script pro

Public exploits

SourceTitleDate
exploit-dbAZ Photo Album Script Pro - Cross-Site Scripting2006-05-23

References

→ the Explorer  ·  watch your stack  ·  NVD