FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-1106

This CVE name corresponds to:

Entered Topic
2005-06-17 gallery -- cross-site scripting

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-1106
Phase Assigned(20041130)

Description

Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.

References

Source Reference
DEBIAN DSA-642
GENTOO GLSA-200411-10
CONFIRM http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=142&mode=thread&order=0&thold=0
MISC http://g3cko.info/gallery2-4.patch
XF gallery-script-xss(17948)
BID 11602