|
AZ Photo Album Script contains a flaw that allows a remote user to execute arbitrary script code. This flaw exists because the program does not properly verify or sanitize user-uploaded files. By uploading a file containing JavaScript code, the remote system will place the file in gallery and render the code in the context of the person viewing the gallery.
|