Back to search
CVE-2008-4130
Published: Sep 18, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
GLSA-200811-02
vendor-advisory
x_refsource_GENTOO
33144
third-party-advisory
x_refsource_SECUNIA
31858
third-party-advisory
x_refsource_SECUNIA
32662
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-11258
vendor-advisory
x_refsource_FEDORA
gallery-flashanimations-xss(45227)
vdb-entry
x_refsource_XF
31231
vdb-entry
x_refsource_BID
http://gallery.menalto.com/gallery_2.2.6_released
x_refsource_CONFIRM
FEDORA-2008-11230
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now