1 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 7EXPL: 0

14 May 2014 — Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php. Múltiples vulnerabilidades de XSS en Gallery 3 anterior a 3.0.7 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de (1) el título de película hacia modules/gallery/controllers/movies.php o (2) la... • http://galleryproject.org/gallery_3_0_7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •