CVE-2012-1113

Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:maian:gallery:2.3:*:*:*:*:*:*:*
cpe:2.3:a:maian:gallery:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:menalto:gallery:2.2.6:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:maian:gallery:3.0:*:*:*:*:*:*:*
cpe:2.3:a:maian:gallery:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:maian:gallery:3.0.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:36

Type Values Removed Values Added
References () http://gallery.menalto.com/gallery_3_0_3_and_gallery_2_3_2 - () http://gallery.menalto.com/gallery_3_0_3_and_gallery_2_3_2 -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078618.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078618.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078752.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078752.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078816.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078816.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078851.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078851.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078873.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078873.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078925.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078925.html -
References () http://secunia.com/advisories/48767 - () http://secunia.com/advisories/48767 -
References () http://www.securityfocus.com/bid/52996 - () http://www.securityfocus.com/bid/52996 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=812045 - () https://bugzilla.redhat.com/show_bug.cgi?id=812045 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/74837 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/74837 -

Information

Published : 2012-04-22 18:55

Updated : 2024-11-21 01:36


NVD link : CVE-2012-1113

Mitre link : CVE-2012-1113

CVE.ORG link : CVE-2012-1113


JSON object : View

Products Affected

menalto

  • gallery

maian

  • gallery
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')