CVE-2004-1106: XSS
Published Dec 1, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.
Affected Software
8 affected components
Gallery Project Gallery=1.4
Gallery Project Gallery=1.4.1
Gallery Project Gallery=1.4.2
Gallery Project Gallery=1.4.3_pl1
Gallery Project Gallery=1.4.3_pl2
Gallery Project Gallery=1.4_pl1
Gallery Project Gallery=1.4_pl2
Gentoo Linux
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 1, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1106?
CVE-2004-1106 is classified as a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2004-1106?
To fix CVE-2004-1106, upgrade to a patched version of Gallery that is not affected by this vulnerability.
3
What versions of Gallery are affected by CVE-2004-1106?
CVE-2004-1106 affects Gallery versions 1.4.4-pl3 and earlier.
4
Can CVE-2004-1106 lead to data theft?
Yes, CVE-2004-1106 can allow attackers to execute arbitrary scripts, potentially leading to data theft.
5
Is CVE-2004-1106 specific to any operating system?
CVE-2004-1106 is not specific to any operating system but affects the Gallery application across various environments.