First published: Thu Sep 18 2008(Updated: )
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Gallery | =2.2.0 | |
NotFound Gallery | =2.2.3 | |
NotFound Gallery | =2.2.2 | |
NotFound Gallery | =2.2.4 | |
NotFound Gallery | <=2.2.5 | |
NotFound Gallery | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4130 has a medium severity level as it allows remote attackers to inject arbitrary web scripts into affected Gallery installations.
To fix CVE-2008-4130, you should upgrade Gallery to version 2.2.6 or later, where the vulnerability is addressed.
CVE-2008-4130 affects Gallery versions from 2.2.0 up to and including 2.2.5.
CVE-2008-4130 allows attackers to perform cross-site scripting (XSS) attacks via crafted Flash animations.
CVE-2008-4130 is specific to the Gallery web application, particularly versions from 2.2.0 to 2.2.5.