CVE-2006-1127: XSS
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (XFORWARDEDFOR) HTTP header, which is not properly handled when adding a comment to an album.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1127?
CVE-2006-1127 is classified as a medium severity vulnerability that allows for cross-site scripting (XSS).
How do I fix CVE-2006-1127?
To fix CVE-2006-1127, upgrade Gallery to version 2.0.3 or later, which addresses the cross-site scripting issue.
Which versions of Gallery are affected by CVE-2006-1127?
CVE-2006-1127 affects Gallery versions up to and including 2.0.2 and all alpha and beta versions prior to 2.0.3.
What type of attack is possible due to CVE-2006-1127?
An attacker can exploit CVE-2006-1127 to inject arbitrary web scripts or HTML into the comments section of an album.
Is it safe to use Gallery version 2.0.2 with CVE-2006-1127?
Using Gallery version 2.0.2 is not safe due to the unresolved cross-site scripting vulnerability identified by CVE-2006-1127.