Vulnerability Description
Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gallery Project | Gallery | 1.4 |
| Gentoo | Linux | All versions |
References
- http://g3cko.info/gallery2-4.patchURL Repurposed
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=142
- http://www.debian.org/security/2005/dsa-642Patch
- http://www.gentoo.org/security/en/glsa/glsa-200411-10.xmlPatchVendor Advisory
- http://www.securityfocus.com/bid/11602PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17948
- http://g3cko.info/gallery2-4.patchURL Repurposed
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=142
- http://www.debian.org/security/2005/dsa-642Patch
- http://www.gentoo.org/security/en/glsa/glsa-200411-10.xmlPatchVendor Advisory
- http://www.securityfocus.com/bid/11602PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17948
FAQ
What is CVE-2004-1106?
CVE-2004-1106 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include paramete...
How severe is CVE-2004-1106?
CVE-2004-1106 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1106?
Check the references section above for vendor advisories and patch information. Affected products include: Gallery Project Gallery, Gentoo Linux.