Vulnerabilities > CVE-2005-0219 - Cross-Site Scripting vulnerability in Gallery Project Gallery 1.3.4Pl1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
gallery-project
nessus

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php.

Vulnerable Configurations

Part Description Count
Application
Gallery_Project
1

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_5752A0DF60C54876A872F12F9A02FA05.NASL
descriptionGallery includes several cross-site scripting vulnerabilities that could allow malicious content to be injected.
last seen2020-06-01
modified2020-06-02
plugin id18940
published2005-07-13
reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/18940
titleFreeBSD : gallery -- XSS (5752a0df-60c5-4876-a872-f12f9a02fa05)