Gallery Script Injection Vulnerability
BID:14668
Info
Gallery Script Injection Vulnerability
| Bugtraq ID: | 14668 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2734 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2005 12:00AM |
| Updated: | Oct 11 2006 06:54PM |
| Credit: | Cedric Cochin is credited with the discovery of this vulnerability. |
| Vulnerable: |
Gallery Gallery 1.5.1 -RC2 Gallery Gallery 1.5.1 Gallery Gallery 1.5 Gallery Gallery 1.4.4 -pl5 Gallery Gallery 1.4.4 -pl4 Gallery Gallery 1.4.4 -pl3 Gallery Gallery 1.4.4 -pl2 Gallery Gallery 1.4.3 -pl2 Gallery Gallery 1.4.3 -pl1 Gallery Gallery 1.4.2 Gallery Gallery 1.4.1 Gallery Gallery 1.4 -pl2 Gallery Gallery 1.4 -pl1 Gallery Gallery 1.4 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Gallery Gallery 2.0 Alpha Gallery Gallery 1.5.1 Gallery Gallery 1.5 -pl1 |
Discussion
Gallery Script Injection Vulnerability
Gallery is prone to a script-injection vulnerability because it fails to properly sanitize user-supplied input.
A malicious user may cause arbitrary script code to execute in the browser context of an unsuspecting victim. This may let the attacker steal cookie-based authentication credentials in the context of the victim's browser; further attacks are also possible.
Gallery is prone to a script-injection vulnerability because it fails to properly sanitize user-supplied input.
A malicious user may cause arbitrary script code to execute in the browser context of an unsuspecting victim. This may let the attacker steal cookie-based authentication credentials in the context of the victim's browser; further attacks are also possible.
Exploit / POC
Gallery Script Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gallery Script Injection Vulnerability
Solution:
The vendor has released Gallery 1.5-pl1 Security Release and Gallery 1.5.1-RC3 Preview Release to address this issue.
Please see the referenced advisories for more information.
Gallery Gallery 1.4 -pl2
Gallery Gallery 1.4 -pl1
Gallery Gallery 1.4
Gallery Gallery 1.4.1
Gallery Gallery 1.4.2
Gallery Gallery 1.4.3 -pl2
Gallery Gallery 1.4.3 -pl1
Gallery Gallery 1.4.4 -pl5
Gallery Gallery 1.4.4 -pl4
Gallery Gallery 1.4.4 -pl3
Gallery Gallery 1.4.4 -pl2
Gallery Gallery 1.5
Gallery Gallery 1.5.1
Gallery Gallery 1.5.1 -RC2
Solution:
The vendor has released Gallery 1.5-pl1 Security Release and Gallery 1.5.1-RC3 Preview Release to address this issue.
Please see the referenced advisories for more information.
Gallery Gallery 1.4 -pl2
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4 -pl1
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.1
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.2
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.3 -pl2
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.3 -pl1
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.4 -pl5
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.4 -pl4
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.4 -pl3
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.4.4 -pl2
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.5
-
Debian gallery_1.5-1sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.5-1sa rge2_all.deb -
Gallery gallery-1.5-pl1.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5-pl1.tar.gz -
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.5.1
-
Gallery gallery-1.5.1-RC3
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064 -
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
Gallery Gallery 1.5.1 -RC2
-
Gallery gallery-2.0-rc-2-full.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-2.0-rc-2-full.tar.g z
References
Gallery Script Injection Vulnerability
References:
References:
- Gallery Product Page (Gallery)
- Gallery Security and Preview Release (Gallery)
- Multiple PHP Images Galleries EXIF Metadata XSS Vulnerabilities (Cedric Cochin)