Gallery Multiple Remote Vulnerabilities...

- AV AC AU C I A
发布: 2005-01-17
修订: 2025-04-13

Gallery is reported prone to multiple remote vulnerabilities. The following issues are reported: It is reported that multiple cross-site scripting issues exist in Gallery. These vulnerabilities exist because user-supplied input is not sufficiently sanitized before this input is included in dynamically rendered HTML pages that are returned to a user. These issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected Web site and may allow for theft of cookie-based authentication credentials or other attacks. An information disclosure vulnerability is reported to affect Gallery version 2.0 Alpha. It is reported that under some circumstances Gallery may return an error message that contains the installation path of the vulnerable Gallery installation. A remote attacker may...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息