Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Gallery Unspecified Remote HTML Injection Vulnerability

An unspecified HTML injection vulnerability reportedly affects Gallery. This issue is due to a failure of the application to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Update: It is reported that the fixes released by the vendor to address this issue are ineffective. Gallery 1.4.4-pl2 is still considered vulnerable to cross-site scripting attacks. Gallery 1.4.4-pl2 is being added to affected packages and the fixes are being removed as well.







 

Privacy Statement
Copyright 2008, SecurityFocus