First published: Sat Jan 21 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gallery Project Gallery | =1.4.3_pl2 | |
Gallery Project Gallery | =1.4.4_pl2 | |
Gallery Project Gallery | =1.4_pl1 | |
Gallery Project Gallery | =1.4.2 | |
Gallery Project Gallery | =1.5.1 | |
Gallery Project Gallery | =1.5 | |
Gallery Project Gallery | =1.4.4_pl3 | |
Gallery Project Gallery | =1.4.1 | |
Gallery Project Gallery | =1.5.1_rc2 | |
Gallery Project Gallery | =1.4.3_pl1 | |
Gallery Project Gallery | =1.4.4_pl4 | |
Gallery Project Gallery | =1.5.2_rc2 | |
Gallery Project Gallery | =1.4.4_pl5 | |
Gallery Project Gallery | =1.3.4 | |
Gallery Project Gallery | =1.4_pl2 | |
Gallery Project Gallery | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0330 has a moderate severity rating due to the potential for cross-site scripting attacks.
To fix CVE-2006-0330, upgrade to Gallery version 1.5.2 or later.
CVE-2006-0330 affects Gallery versions from 1.3.4 to 1.5.1, including various 1.4 and 1.4.4 patch levels.
Yes, CVE-2006-0330 can be exploited remotely through cross-site scripting via user input.
CVE-2006-0330 can lead to arbitrary script or HTML injection attacks, posing risks to user data.