First published: Mon Aug 29 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GalleryCMS | =1.4 | |
GalleryCMS | =1.4.1 | |
GalleryCMS | =1.4.2 | |
GalleryCMS | =1.4.3_pl1 | |
GalleryCMS | =1.4.3_pl2 | |
GalleryCMS | =1.4.4_pl2 | |
GalleryCMS | =1.4.4_pl3 | |
GalleryCMS | =1.4.4_pl4 | |
GalleryCMS | =1.4.4_pl5 | |
GalleryCMS | =1.4_pl1 | |
GalleryCMS | =1.4_pl2 | |
GalleryCMS | =1.5 | |
GalleryCMS | =1.5.1 | |
GalleryCMS | =1.5.1_rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2734 is classified as a moderate severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
To fix CVE-2005-2734, upgrade your Gallery installation to version 1.5.1 or later, where the issue has been addressed.
CVE-2005-2734 affects Gallery versions up to and including 1.5.1-RC2 and earlier.
The impact of CVE-2005-2734 allows remote attackers to inject arbitrary web scripts or HTML via manipulated EXIF data.
Currently, there are no documented workarounds for mitigating CVE-2005-2734; upgrading is recommended as the best solution.