Vulnerabilities > CVE-2005-2676 - Unspecified vulnerability in Coppermine Photo Gallery
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN coppermine
nessus
Summary
Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data.
Vulnerable Configurations
Nessus
NASL family | CGI abuses : XSS |
NASL id | COPPERMINE_GALLERY_EXIF_XSS.NASL |
description | According to its banner, the version of Coppermine Gallery installed on the remote host is prone to cross-site scripting attacks because it does not sanitize malicious EXIF data stored in image files. Using a specially crafted image file, an attacker can exploit this flaw to cause arbitrary HTML and script code to be executed in a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19511 |
published | 2005-08-27 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19511 |
title | Coppermine Photo Gallery EXIF Data XSS |
code |
|
References
- http://coppermine-gallery.net/forum/index.php?topic=20933.0
- http://coppermine-gallery.net/forum/index.php?topic=20933.0
- http://secunia.com/advisories/16499
- http://secunia.com/advisories/16499
- http://securitytracker.com/id?1014799
- http://securitytracker.com/id?1014799
- http://www.securityfocus.com/bid/14625
- http://www.securityfocus.com/bid/14625