Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in addcomment.php, (2) setalbumName, (3) slideindex, (4) slidefull, (5) slideloop, (6) slidepause, (7) slidedir fields in slideshowlow.php, or (8) username field in search.php.