CVE-2005-2734: XSS
Published Aug 29, 2005
·Updated
Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.
Affected Software
14 affected components
Gallery Project Gallery=1.4
Gallery Project Gallery=1.4.1
Gallery Project Gallery=1.4.2
Gallery Project Gallery=1.4.3_pl1
Gallery Project Gallery=1.4.3_pl2
Gallery Project Gallery=1.4.4_pl2
Gallery Project Gallery=1.4.4_pl3
Gallery Project Gallery=1.4.4_pl4
Gallery Project Gallery=1.4.4_pl5
Gallery Project Gallery=1.4_pl1
Gallery Project Gallery=1.4_pl2
Gallery Project Gallery=1.5
Gallery Project Gallery=1.5.1
Gallery Project Gallery=1.5.1_rc2
Remediation
Event History
Aug 29, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2734?
CVE-2005-2734 is classified as a moderate severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
2
How do I fix CVE-2005-2734?
To fix CVE-2005-2734, upgrade your Gallery installation to version 1.5.1 or later, where the issue has been addressed.
3
Which versions of Gallery are affected by CVE-2005-2734?
CVE-2005-2734 affects Gallery versions up to and including 1.5.1-RC2 and earlier.
4
What is the impact of CVE-2005-2734?
The impact of CVE-2005-2734 allows remote attackers to inject arbitrary web scripts or HTML via manipulated EXIF data.
5
Is there a workaround for CVE-2005-2734 if I can't update?
Currently, there are no documented workarounds for mitigating CVE-2005-2734; upgrading is recommended as the best solution.