Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the album parameter.Referenceshttp://www.securityfocus.com/bid/41382http://www.vupen.com/english/advisories/2010/1696http://www.exploit-db.com/exploits/14203https://exchange.xforce.ibmcloud.com/vulnerabilities/60078