Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2006-1219
Disclosure Date: March 14, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.
0
Attacker Value
Unknown
CVE-2006-1127
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.
0
Attacker Value
Unknown
CVE-2006-1128
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.
0
Attacker Value
Unknown
CVE-2005-4021
Disclosure Date: December 05, 2005 (last updated February 22, 2025)
The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2005-3251
Disclosure Date: October 17, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.
0