CVE-2006-1696: XSS
Published Apr 11, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Affected Software
20 affected components
Gallery Project Gallery=1.3.4
Gallery Project Gallery=1.4
Gallery Project Gallery=1.4.1
Gallery Project Gallery=1.4.2
Gallery Project Gallery=1.4.3_pl1
Gallery Project Gallery=1.4.3_pl2
Gallery Project Gallery=1.4.4_pl2
Gallery Project Gallery=1.4.4_pl3
Gallery Project Gallery=1.4.4_pl4
Gallery Project Gallery=1.4.4_pl5
Gallery Project Gallery=1.4_pl1
Gallery Project Gallery=1.4_pl2
Gallery Project Gallery=1.5
Gallery Project Gallery=1.5.1
Gallery Project Gallery=1.5.1_rc2
Gallery Project Gallery=1.5.2
Gallery Project Gallery=1.5.2_pl1
Gallery Project Gallery=1.5.2_pl2
Gallery Project Gallery=1.5.2_rc2
Gallery Project Gallery=1.5.2_rc3
Remediation
Patch Available
Event History
Apr 11, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1696?
CVE-2006-1696 is classified as a medium-severity vulnerability due to its potential for causing cross-site scripting attacks.
2
How do I fix CVE-2006-1696?
To fix CVE-2006-1696, upgrade to Gallery version 1.5.3 or later, which provides the necessary patches.
3
What types of attacks can CVE-2006-1696 enable?
CVE-2006-1696 can enable remote attackers to inject arbitrary web script or HTML, facilitating data theft or manipulation.
4
Which versions of Gallery are affected by CVE-2006-1696?
CVE-2006-1696 affects Gallery versions prior to 1.5.3, including 1.3.4, 1.4.x, and 1.5.x versions.
5
Is CVE-2006-1696 still a threat today?
While CVE-2006-1696 is an older vulnerability, unpatched systems running affected versions remain at risk to ongoing exploitation.