4.3
CVSSv2

CVE-2006-0330

Published: 21/01/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Gallery prior to 1.5.2 allows remote malicious users to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 1.4.3 pl2

gallery project gallery 1.4.4 pl2

gallery project gallery 1.4 pl1

gallery project gallery 1.4.2

gallery project gallery 1.5.1

gallery project gallery 1.5

gallery project gallery 1.4.4 pl3

gallery project gallery 1.4.1

gallery project gallery 1.5.1 rc2

gallery project gallery 1.4.3 pl1

gallery project gallery 1.4.4 pl4

gallery project gallery 1.5.2 rc2

gallery project gallery 1.4.4 pl5

gallery project gallery 1.3.4

gallery project gallery 1.4 pl2

gallery project gallery 1.4

Vendor Advisories

Several remote vulnerabilities have been discovered in gallery, a web-based photo album The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-2734 A cross-site scripting vulnerability allows injection of web script code through HTML or EXIF information CVE-2006-0330 A cross-site scripting vulner ...