|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200501-45] Gallery: Cross-site scripting vulnerability Vulnerability Assessment Details
|
[GLSA-200501-45] Gallery: Cross-site scripting vulnerability |
||
Gallery: Cross-site scripting vulnerability Detailed Explanation for this Vulnerability Assessment The remote host is affected by the vulnerability described in GLSA-200501-45 (Gallery: Cross-site scripting vulnerability) Rafel Ivgi has discovered a cross-site scripting vulnerability where the 'username' parameter is not properly sanitized in 'login.php'. Impact By sending a carefully crafted URL, a possible hacker can inject and execute script code in the victim's browser window, and potentially compromise the user's gallery. Workaround There is no known workaround at this time. References: http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=149 http://secunia.com/advisories/13887/ Solution: All Gallery users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/gallery-1.4.4_p6" Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update. Network Security Threat Level: Low Networks Security ID: Vulnerability Assessment Copyright: (C) 2005 Michel Arboi |
||
Cables, Connectors |
Extron RGB-160XI Analog Computer Video 60-378-01
$187.06
The analog thing modern open source, educational, low-cost analog computer
$800.00
NEW Aquarius+ Mini 8Bit Retro Computer System - Assembled PCB ONLY
$99.00
IBM Modem Saver Phone Line Tester
$7.99
FULLY RECAPPED MACINTOSH CLASSIC II 2 VINTAGE MAC APPLE COMPUTER NEW BATT WORKS
$899.00
Landen Computer. Circa 1898. the Rapid Computer Company. With Original Case.
$425.00
Apple Macintosh Plus Completely Recapped #M0001A 4MB
$499.00
Macintosh Plus, BlueSCSI, OS 6.x, 4 mb memory - recapped, tested, working.
$715.00
Macintosh Classic/Classic II Analog Board Computer 630-0395 New
$278.00
ACASIS PCIE Capture Card HDMI 1.4 1080P60HZ PCIE 2.0 X4 20Gbps for Video Capture
$248.99
|
||
No Discussions have been posted on this vulnerability. |