CVE-2005-4022

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gallery_project:gallery:2.0:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha2:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha3:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha4:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_beta1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_beta2:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_beta3:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_rc1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_rc2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://secunia.com/advisories/17747 - Patch, Vendor Advisory () http://secunia.com/advisories/17747 - Patch, Vendor Advisory
References () http://www.osvdb.org/21221 - Patch, Vendor Advisory () http://www.osvdb.org/21221 - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/418200/100/0/threaded - () http://www.securityfocus.com/archive/1/418200/100/0/threaded -
References () http://www.securityfocus.com/bid/15614 - () http://www.securityfocus.com/bid/15614 -
References () http://www.vupen.com/english/advisories/2005/2681 - () http://www.vupen.com/english/advisories/2005/2681 -

Information

Published : 2005-12-05 11:03

Updated : 2025-04-03 01:03


NVD link : CVE-2005-4022

Mitre link : CVE-2005-4022

CVE.ORG link : CVE-2005-4022


JSON object : View

Products Affected

gallery_project

  • gallery