Vulnerabilities > CVE-2005-0220 - Cross-Site Scripting vulnerability in Gallery Project Gallery 1.4.4Pl2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
gallery-project
nessus

Summary

Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.

Vulnerable Configurations

Part Description Count
Application
Gallery_Project
1

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_5752A0DF60C54876A872F12F9A02FA05.NASL
    descriptionGallery includes several cross-site scripting vulnerabilities that could allow malicious content to be injected.
    last seen2020-06-01
    modified2020-06-02
    plugin id18940
    published2005-07-13
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/18940
    titleFreeBSD : gallery -- XSS (5752a0df-60c5-4876-a872-f12f9a02fa05)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200501-45.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200501-45 (Gallery: XSS vulnerability) Rafel Ivgi has discovered a cross-site scripting vulnerability where the
    last seen2020-06-01
    modified2020-06-02
    plugin id16436
    published2005-02-14
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/16436
    titleGLSA-200501-45 : Gallery: XSS vulnerability
  • NASL familyCGI abuses : XSS
    NASL idGALLERY_MULTIPLE_ISSUES.NASL
    descriptionThe version of Gallery hosted on the remote web server is affected by a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to the
    last seen2020-06-01
    modified2020-06-02
    plugin id16185
    published2005-01-18
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16185
    titleGallery login.php username Parameter XSS