Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 26790

Summary: dev-php/gallery
Product: Gentoo Linux Reporter: Daniel Ahlberg (RETIRED) <aliz>
Component: New packagesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: critical    
Priority: Highest    
Version: 1.0   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-08-17 02:52:05 UTC
-------------------------------------------------------------------------- 
Debian Security Advisory DSA 355-1                     security@debian.org 
http://www.debian.org/security/                             Matt Zimmerman 
July 30th, 2003                         http://www.debian.org/security/faq 
-------------------------------------------------------------------------- 
 
Package        : gallery 
Vulnerability  : cross-site scripting 
Problem-Type   : remote 
Debian-specific: no 
CVE Ids        : CAN-2003-0614 
 
Larry Nguyen discovered a cross site scripting vulnerability in gallery, 
a web-based photo album written in php.  This security flaw can allow a 
malicious user to craft a URL that executes Javascript code on your 
website.
Comment 1 Daniel Ahlberg (RETIRED) gentoo-dev 2003-09-02 04:01:01 UTC
glsa sent