6.8
CVSSv2

CVE-2004-1106

Published: 10/01/2005 Updated: 14/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and previous versions allows remote malicious users to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 1.4.3_pl2

gallery project gallery 1.4_pl1

gallery project gallery 1.4.2

gallery project gallery 1.4.1

gallery project gallery 1.4.3_pl1

gallery project gallery 1.4_pl2

gallery project gallery 1.4

gentoo linux

Vendor Advisories

Several vulnerabilities have been discovered in gallery, a web-based photo album written in PHP4 The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CAN-2004-1106 Jim Paris discovered a cross site scripting vulnerability which allows code to be inserted by using specially formed URLs CVE-NOMATCH ...