PT-2005-4065 · Gallery · Gallery 2.0
Michael Dipper
·
Publicado
2005-10-17
·
Atualizado
2008-09-05
·
CVE-2005-3251
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Gallery 2.0 (G2)
Description
A directory traversal issue in the gallery script allows remote attackers to read or include arbitrary files by using ".." sequences in the
g2 itemId parameter.Recommendations
For Gallery 2.0 (G2), avoid using the
g2 itemId parameter with ".." sequences until a patch is available. As a temporary workaround, consider restricting access to the gallery script to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gallery 2.0