6.4
CVSSv2

CVE-2006-1128

Published: 09/03/2006 Updated: 20/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote malicious users to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 2.0

gallery project gallery 2.0_alpha4

gallery project gallery 2.0_beta1

gallery project gallery 2.0_beta2

gallery project gallery 2.0.1

gallery project gallery 2.0.2

gallery project gallery 2.0_beta3

gallery project gallery 2.0_alpha

gallery project gallery 2.0_alpha1

gallery project gallery 2.0_alpha2

gallery project gallery 2.0_alpha3

Exploits

Gallery 2 Multiple Vulnerabilities Vendor: Bharat Mediratta Product: Gallery 2 Version: <= 202 Website: gallerymenaltocom/ BID: 16940 CVE: CVE-2006-1127 CVE-2006-1128 OSVDB: 23596 23597 SECUNIA: 19104 PACKETSTORM: 44358 Description: Gallery2, the open source web based photo album organizer is one of the most popular php web ap ...