Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
http://www.openwall.com/lists/oss-security/2011/06/08/6
http://www.openwall.com/lists/oss-security/2011/06/08/2
http://forum.coppermine-gallery.net/index.php/topic%2C65023.msg322935.html