CVE-2008-4130: XSS
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4130?
CVE-2008-4130 has a medium severity level as it allows remote attackers to inject arbitrary web scripts into affected Gallery installations.
How do I fix CVE-2008-4130?
To fix CVE-2008-4130, you should upgrade Gallery to version 2.2.6 or later, where the vulnerability is addressed.
Which versions are affected by CVE-2008-4130?
CVE-2008-4130 affects Gallery versions from 2.2.0 up to and including 2.2.5.
What kind of attack can be executed due to CVE-2008-4130?
CVE-2008-4130 allows attackers to perform cross-site scripting (XSS) attacks via crafted Flash animations.
Is CVE-2008-4130 specific to certain platforms?
CVE-2008-4130 is specific to the Gallery web application, particularly versions from 2.2.0 to 2.2.5.