Unrated severityNVD Advisory· Published Sep 18, 2008· Updated Apr 23, 2026
CVE-2008-4130
CVE-2008-4130
Description
Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."
Affected products
6cpe:2.3:a:gallery:gallery:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gallery:gallery:*:*:*:*:*:*:*:*range: <=2.2.5
- cpe:2.3:a:gallery:gallery:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:gallery:gallery:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gallery:gallery:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:gallery:gallery:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:gallery:gallery:2.2.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- gallery.menalto.com/gallery_2.2.6_releasednvdPatch
- secunia.com/advisories/31858nvd
- secunia.com/advisories/32662nvd
- secunia.com/advisories/33144nvd
- security.gentoo.org/glsa/glsa-200811-02.xmlnvd
- www.securityfocus.com/bid/31231nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45227nvd
- www.redhat.com/archives/fedora-package-announce/2008-December/msg00794.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-December/msg00832.htmlnvd
News mentions
0No linked articles in our index yet.