Gallery Unspecified Cross-Site Scripting Vulnerability
BID:17437
Info
Gallery Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 17437 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2006 12:00AM |
| Updated: | Apr 11 2006 06:42PM |
| Credit: | Aditya Mooley is credited with the discovery of this vulnerability. |
| Vulnerable: |
Gallery Gallery 1.5.2 -RC2 Gallery Gallery 1.5.2 -pl2 Gallery Gallery 1.5.2 Gallery Gallery 1.5.1 -RC2 Gallery Gallery 1.5.1 Gallery Gallery 1.5 -pl1 Gallery Gallery 1.5 Gallery Gallery 1.4.4 -pl5 Gallery Gallery 1.4.4 -pl4 Gallery Gallery 1.4.4 -pl3 Gallery Gallery 1.4.4 -pl2 Gallery Gallery 1.4.3 -pl2 Gallery Gallery 1.4.3 -pl1 Gallery Gallery 1.4.2 Gallery Gallery 1.4.1 Gallery Gallery 1.4 -pl2 Gallery Gallery 1.4 -pl1 Gallery Gallery 1.4 |
| Not Vulnerable: |
Gallery Gallery 1.5.3 |
Discussion
Gallery Unspecified Cross-Site Scripting Vulnerability
Gallery is prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Gallery is prone to an unspecified cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Gallery Unspecified Cross-Site Scripting Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
Gallery Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor has released version 1.5.3 to address this issue.
Gallery Gallery 1.4 -pl2
Gallery Gallery 1.4 -pl1
Gallery Gallery 1.4
Gallery Gallery 1.4.1
Gallery Gallery 1.4.2
Gallery Gallery 1.4.3 -pl2
Gallery Gallery 1.4.3 -pl1
Gallery Gallery 1.4.4 -pl5
Gallery Gallery 1.4.4 -pl3
Gallery Gallery 1.4.4 -pl4
Gallery Gallery 1.4.4 -pl2
Gallery Gallery 1.5
Gallery Gallery 1.5 -pl1
Gallery Gallery 1.5.1
Gallery Gallery 1.5.1 -RC2
Gallery Gallery 1.5.2 -pl2
Gallery Gallery 1.5.2
Gallery Gallery 1.5.2 -RC2
Solution:
The vendor has released version 1.5.3 to address this issue.
Gallery Gallery 1.4 -pl2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4 -pl1
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.1
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.3 -pl2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.3 -pl1
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.4 -pl5
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.4 -pl3
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.4 -pl4
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.4.4 -pl2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5 -pl1
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5.1
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5.1 -RC2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5.2 -pl2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5.2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
Gallery Gallery 1.5.2 -RC2
-
Gallery gallery-1.5.3.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.3.tar.gz
References
Gallery Unspecified Cross-Site Scripting Vulnerability
References:
References:
- Gallery Product Page (Gallery)
- Release Name: 1.5.3 (Gallery)