5
CVSSv2

CVE-2005-3432

Published: 02/11/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

MiniGal 2 (MG2) 0.5.1 allows remote malicious users to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.

Vulnerable Product Search on Vulmon Subscribe to Product

thomas rybak minigal 2 0.5.1

thomas rybak minigal 2 b13

Exploits

source: wwwsecurityfocuscom/bid/15235/info MG2 is affected by an authentication bypass vulnerability This issue can allow remote attackers to gain access to password protected image galleries All versions of MG2 are considered to be vulnerable at the moment Minigal B13 is likely affected as well wwwexmaplecom/mg2/indexphp? ...