Vulnerabilities > CVE-2005-0220 - Cross-Site Scripting vulnerability in Gallery Project Gallery 1.4.4Pl2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_5752A0DF60C54876A872F12F9A02FA05.NASL description Gallery includes several cross-site scripting vulnerabilities that could allow malicious content to be injected. last seen 2020-06-01 modified 2020-06-02 plugin id 18940 published 2005-07-13 reporter This script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/18940 title FreeBSD : gallery -- XSS (5752a0df-60c5-4876-a872-f12f9a02fa05) NASL family Gentoo Local Security Checks NASL id GENTOO_GLSA-200501-45.NASL description The remote host is affected by the vulnerability described in GLSA-200501-45 (Gallery: XSS vulnerability) Rafel Ivgi has discovered a cross-site scripting vulnerability where the last seen 2020-06-01 modified 2020-06-02 plugin id 16436 published 2005-02-14 reporter This script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/16436 title GLSA-200501-45 : Gallery: XSS vulnerability NASL family CGI abuses : XSS NASL id GALLERY_MULTIPLE_ISSUES.NASL description The version of Gallery hosted on the remote web server is affected by a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to the last seen 2020-06-01 modified 2020-06-02 plugin id 16185 published 2005-01-18 reporter This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/16185 title Gallery login.php username Parameter XSS
References
- http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=147
- http://marc.info/?l=bugtraq&m=110608459222364&w=2
- http://secunia.com/advisories/13887/
- http://theinsider.deep-ice.com/texts/advisory69.txt
- http://www.gentoo.org/security/en/glsa/glsa-200501-45.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18938