CVE-2006-0330: XSS
Published Jan 21, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).
Affected Software
16 affected components
Gallery Project Gallery=1.3.4
Gallery Project Gallery=1.4
Gallery Project Gallery=1.4.1
Gallery Project Gallery=1.4.2
Gallery Project Gallery=1.4.3_pl1
Gallery Project Gallery=1.4.3_pl2
Gallery Project Gallery=1.4.4_pl2
Gallery Project Gallery=1.4.4_pl3
Gallery Project Gallery=1.4.4_pl4
Gallery Project Gallery=1.4.4_pl5
Gallery Project Gallery=1.4_pl1
Gallery Project Gallery=1.4_pl2
Gallery Project Gallery=1.5
Gallery Project Gallery=1.5.1
Gallery Project Gallery=1.5.1_rc2
Gallery Project Gallery=1.5.2_rc2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jan 21, 2006
CVE Published
12:03 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0330?
CVE-2006-0330 has a moderate severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2006-0330?
To fix CVE-2006-0330, upgrade to Gallery version 1.5.2 or later.
3
What versions are affected by CVE-2006-0330?
CVE-2006-0330 affects Gallery versions from 1.3.4 to 1.5.1, including various 1.4 and 1.4.4 patch levels.
4
Can CVE-2006-0330 be exploited remotely?
Yes, CVE-2006-0330 can be exploited remotely through cross-site scripting via user input.
5
What kind of attacks can CVE-2006-0330 lead to?
CVE-2006-0330 can lead to arbitrary script or HTML injection attacks, posing risks to user data.