First published: Tue Aug 23 2005(Updated: )
Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Photo Gallery | =1.0_rc3 | |
Coppermine Photo Gallery | =1.1_.0 | |
Coppermine Photo Gallery | =1.1_beta_2 | |
Coppermine Photo Gallery | =1.2 | |
Coppermine Photo Gallery | =1.2.1 | |
Coppermine Photo Gallery | =1.2.2_b | |
Coppermine Photo Gallery | =1.3 | |
Coppermine Photo Gallery | =1.3.2 | |
Coppermine Photo Gallery | =1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2676 is classified as a moderate severity vulnerability due to its potential for XSS attacks.
To fix CVE-2005-2676, upgrade to Coppermine Photo Gallery version 1.3.4 or later to eliminate the XSS vulnerability.
CVE-2005-2676 affects Coppermine Photo Gallery versions prior to 1.3.4, including 1.1 beta 2, 1.2, 1.3.2, 1.0 rc3, and others.
CVE-2005-2676 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts into the site.
Users of Coppermine Photo Gallery who have not updated to a secure version may be impacted by CVE-2005-2676.