CVE-2008-4130
Gentoo Linux Security Advisory 200811-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."
Vulnerabilidad de secuencias de comandos en sitios cruzados - XSS en Gallery 2.x y versiones anteriores a 2.2.6 que permite a los atacantes remotos inyectar una secuencia de comandos web o HTML arbitrarios a través de una animación Flash manitulada, en relación a la habilidad de la animación a "interactuar con la página incrustada"
Multiple vulnerabilities in Gallery may lead to execution of arbitrary code, disclosure of local files or theft of user's credentials. Versions less than 2.2.6 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-18 CVE Reserved
- 2008-09-18 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/31858 | Third Party Advisory | |
http://secunia.com/advisories/32662 | Third Party Advisory | |
http://secunia.com/advisories/33144 | Third Party Advisory | |
http://www.securityfocus.com/bid/31231 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45227 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://gallery.menalto.com/gallery_2.2.6_released | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gallery Search vendor "Gallery" | Gallery Search vendor "Gallery" for product "Gallery" | <= 2.2.5 Search vendor "Gallery" for product "Gallery" and version " <= 2.2.5" | - |
Affected
| ||||||
Gallery Search vendor "Gallery" | Gallery Search vendor "Gallery" for product "Gallery" | 2.2.0 Search vendor "Gallery" for product "Gallery" and version "2.2.0" | - |
Affected
| ||||||
Gallery Search vendor "Gallery" | Gallery Search vendor "Gallery" for product "Gallery" | 2.2.1 Search vendor "Gallery" for product "Gallery" and version "2.2.1" | - |
Affected
| ||||||
Gallery Search vendor "Gallery" | Gallery Search vendor "Gallery" for product "Gallery" | 2.2.2 Search vendor "Gallery" for product "Gallery" and version "2.2.2" | - |
Affected
| ||||||
Gallery Search vendor "Gallery" | Gallery Search vendor "Gallery" for product "Gallery" | 2.2.3 Search vendor "Gallery" for product "Gallery" and version "2.2.3" | - |
Affected
| ||||||
Gallery Search vendor "Gallery" | Gallery Search vendor "Gallery" for product "Gallery" | 2.2.4 Search vendor "Gallery" for product "Gallery" and version "2.2.4" | - |
Affected
|