Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.
- http://www.packetstormsecurity.com/1006-exploits/candid-sql.txt
No PoCs found on GitHub currently.