LWN.net Logo

gallery: cross-site scripting vulnerability

gallery: cross-site scripting vulnerability

Posted Feb 2, 2006 5:10 UTC (Thu) by mattdm (subscriber, #18)
Parent article: gallery: cross-site scripting vulnerability

Actually, despite what the report says, I think there is a workaround which is valid for many or most deployments of Gallery -- don't give out gallery user accounts to other people. Visitors without a specific Gallery account (only needed to change things on the site) can't set a fullname, so there's no exploit.

I'm not saying it's not bad, just that it doesn't necessarily affect a lot of installations.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds