PT-2005-1303 · Gallery · Gallery
Rafel Ivgi
+1
·
Published
2005-02-06
·
Updated
2017-07-11
·
CVE-2005-0222
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gallery 2.0 Alpha
Description
The issue allows remote attackers to gain sensitive information by modifying the
g2 subView parameter in the main.php file, which reveals the path in an error message.Recommendations
For Gallery 2.0 Alpha, consider restricting access to the
main.php file or avoiding the use of the g2 subView parameter until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gallery