4.3
CVSSv2

CVE-2005-2734

Published: 30/08/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 1.4

gallery project gallery 1.4.1

gallery project gallery 1.4.4_pl5

gallery project gallery 1.4_pl1

gallery project gallery 1.4.2

gallery project gallery 1.4.3_pl1

gallery project gallery 1.4_pl2

gallery project gallery 1.5

gallery project gallery 1.4.3_pl2

gallery project gallery 1.4.4_pl2

gallery project gallery 1.5.1

gallery project gallery 1.5.1_rc2

gallery project gallery 1.4.4_pl3

gallery project gallery 1.4.4_pl4

Vendor Advisories

Several remote vulnerabilities have been discovered in gallery, a web-based photo album The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-2734 A cross-site scripting vulnerability allows injection of web script code through HTML or EXIF information CVE-2006-0330 A cross-site scripting vulner ...