Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michael Dipper

#42380of 53,632
6.4Total CVSS
Vulnerabilities · 1
PT-2005-4065
6.4
2005-10-17
Gallery · Gallery 2.0 · CVE-2005-3251
**Name of the Vulnerable Software and Affected Versions** Gallery 2.0 (G2) **Description** A directory traversal issue in the gallery script allows remote attackers to read or include arbitrary files by using ".." sequences in the `g2 itemId` parameter. **Recommendations** For Gallery 2.0 (G2), avoid using the `g2 itemId` parameter with ".." sequences until a patch is available. As a temporary workaround, consider restricting access to the gallery script to minimize the risk of exploitation.