Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php.
- http://securityreason.com/securityalert/4330
- https://www.exploit-db.com/exploits/6411
No PoCs found on GitHub currently.