Summary
The remote host is missing an update to gallery
announced via advisory DSA 1148-1.
Several remote vulnerabilities have been discovered in gallery, a web-based photo album. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2005-2734
A cross-site scripting vulnerability allows injection of web script code through HTML or EXIF information.
CVE-2006-0330
A cross-site scripting vulnerability in the user registration allows injection of web script code.
CVE-2006-4030
Missing input sanitising in the stats modules allows information disclosure.
Solution
For the stable distribution (sarge) these problems have been fixed in version 1.5-1sarge2.
For the unstable distribution (sid) these problems have been fixed in version 1.5-2.
We recommend that you upgrade your gallery package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201148-1
Severity
Classification
-
CVE CVE-2005-2734, CVE-2006-0330, CVE-2006-4030 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities