Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 268186 - <www-apps/coppermine-1.4.22: XSS
Summary: <www-apps/coppermine-1.4.22: XSS
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial
Assignee: Gentoo Security
URL: http://forum.coppermine-gallery.net/i...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks: 258665 261180
  Show dependency tree
 
Reported: 2009-05-01 21:18 UTC by Alex Legler (RETIRED)
Modified: 2009-06-11 18:44 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2009-05-01 21:18:01 UTC
Via Secunia:

DESCRIPTION:
A vulnerability has been reported in Coppermine Photo Gallery, which
can be exploited by malicious people to conduct cross-site scripting
attacks.

Input passed to the "css" parameter in docs/showdoc.php is not
properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.

SOLUTION:
Update to version 1.4.22.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-06-11 18:44:19 UTC
+*coppermine-1.4.24 (11 Jun 2009)
+
+  11 Jun 2009; Alex Legler <a3li@gentoo.org> -coppermine-1.4.19.ebuild,
+  +coppermine-1.4.24.ebuild:
+  Non-Maintainer commit: Version bump to fix security bugs 261180, 258665,
+  268186 and 273758.
+