First published: Mon Apr 18 2005(Updated: )
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Coppermine Photo Gallery | =1.1_beta_2 | |
Coppermine Coppermine Photo Gallery | =1.2 | |
Coppermine Coppermine Photo Gallery | =1.0_rc3 | |
Coppermine Coppermine Photo Gallery | =1.2.2_b | |
Coppermine Coppermine Photo Gallery | =1.2.1 | |
Coppermine Coppermine Photo Gallery | =1.3 | |
Coppermine Coppermine Photo Gallery | =1.1_.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-1172 is considered high due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2005-1172, upgrade to the latest version of Coppermine Photo Gallery that addresses this vulnerability.
CVE-2005-1172 allows attackers to execute arbitrary web scripts or HTML code in the context of user sessions.
CVE-2005-1172 affects Coppermine Photo Gallery versions 1.0_rc3, 1.1_beta_2, 1.1_.0, 1.2, 1.2.1, 1.2.2_b, and 1.3.
A patch is not specifically mentioned, so upgrading to a full version that resolves the vulnerability is the recommended action.