PT-2008-1654 · Menalto · Menalto Gallery
Published
2008-01-17
·
Updated
2008-11-15
·
CVE-2007-6691
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Menalto Gallery versions prior to 2.2.4
Description
The issue is related to multiple unspecified vulnerabilities in various modules of the Menalto Gallery application, including the URL rewrite module's "hotlink protection", a WebDAV view in the WebDAV module, a comment view in the Comment module, "item information disclosure attacks" in the Core module, the slideshow in the Slideshow module, and multiple Print modules. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations
For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider disabling the affected modules, such as the URL rewrite module, WebDAV module, Comment module, Slideshow module, and Print modules, until a patch is available. Restrict access to the vulnerable components to minimize the risk of exploitation. Avoid using the vulnerable features in the affected modules until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Menalto Gallery