6
CVSSv2

CVE-2010-4353

Published: 25/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery prior to 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

Vulnerable Product Search on Vulmon Subscribe to Product

menalto gallery 2.1.1

menalto gallery 1.6

menalto gallery 2.1.2

menalto gallery 1.5.7

menalto gallery

menalto gallery 2.2.2

menalto gallery 2.1

menalto gallery 2.2.4

menalto gallery 2.2.0

menalto gallery 2.2.3

menalto gallery 2.2.1