5
CVSSv2

CVE-2001-0900

Published: 18/11/2001 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in modules.php in Gallery prior to 1.2.3 allows remote malicious users to read arbitrary files via a .. (dot dot) in the include parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi gallery

Exploits

source: wwwsecurityfocuscom/bid/3554/info Bharat Mediratta Gallery is a free, open source web-based photo album which may be used as an add-on for the PHPNuke web portal Due to insufficient validation of user-supplied input, it is be possible to view arbitrary web-readable files via a specially crafted web request which contains '/' s ...