4.3
CVSSv2

CVE-2006-0330

Published: 21/01/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Gallery prior to 1.5.2 allows remote malicious users to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 1.3.4

gallery project gallery 1.4.4_pl4

gallery project gallery 1.4.4_pl5

gallery project gallery 1.4.3_pl2

gallery project gallery 1.4.4_pl2

gallery project gallery 1.4.4_pl3

gallery project gallery 1.5.1_rc2

gallery project gallery 1.5.2_rc2

gallery project gallery 1.4.2

gallery project gallery 1.4.3_pl1

gallery project gallery 1.5

gallery project gallery 1.5.1

gallery project gallery 1.4

gallery project gallery 1.4.1

gallery project gallery 1.4_pl1

gallery project gallery 1.4_pl2

Vendor Advisories

Several remote vulnerabilities have been discovered in gallery, a web-based photo album The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-2734 A cross-site scripting vulnerability allows injection of web script code through HTML or EXIF information CVE-2006-0330 A cross-site scripting vulner ...