CVE-2013-2087
Publication date 14 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gallery | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |