|
Gallery Unspecified Remote HTML Injection Vulnerability
An unspecified HTML injection vulnerability reportedly affects Gallery. This issue is due to a failure of the application to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. Update: It is reported that the fixes released by the vendor to address this issue are ineffective. Gallery 1.4.4-pl2 is still considered vulnerable to cross-site scripting attacks. Gallery 1.4.4-pl2 is being added to affected packages and the fixes are being removed as well. |
|
|
Privacy Statement |