LWN.net Logo

gallery3: cross-site scripting

Package(s):gallery3 CVE #(s):CVE-2013-2087
Created:May 22, 2013 Updated:May 22, 2013
Description: From the Gallery advisories [1, 2]:

Gallery contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via movie titles before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.

Gallery contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the Error page before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.

Alerts:
Fedora FEDORA-2013-8060 2013-05-22
Fedora FEDORA-2013-8065 2013-05-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds