PT-2006-6714 · Malbum · Malbum
Published
2006-11-22
·
Updated
2018-10-17
·
CVE-2006-6069
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
mAlbum versions 0.3 and earlier
Description
The issue allows remote attackers to obtain the installation path via an invalid
gal parameter in the index.php file.Recommendations
For mAlbum versions 0.3 and earlier, consider restricting access to the
index.php file until a patch is available. As a temporary workaround, avoid using invalid values for the gal parameter to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Malbum