Vulnerability Name: | CVE-2005-2676 (CCN-21973) | ||||||||
Assigned: | 2005-08-22 | ||||||||
Published: | 2005-08-22 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CONFIRM Type: Patch http://coppermine-gallery.net/forum/index.php?topic=20933.0 Source: MITRE Type: CNA CVE-2005-2676 Source: CCN Type: SA16499 Coppermine Photo Gallery EXIF Data Script Insertion Source: SECUNIA Type: UNKNOWN 16499 Source: CCN Type: SECTRACK ID: 1014799 Coppermine Photo Gallery Input Validation Bug in Processing EXIF Meta Data Permits Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1014799 Source: CCN Type: SourceForge.net Project: Coppermine Photo Gallery: Summary Source: CCN Type: OSVDB ID: 18918 Coppermine Photo Gallery EXIF Data XSS Source: BID Type: Patch 14625 Source: CCN Type: BID-14625 Coppermine Displayimage.PHP Script Injection Vulnerability Source: XF Type: UNKNOWN coppermine-exif-script-injection(21973) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |