Vulnerability Name: | CVE-2005-3251 (CCN-22747) | ||||||||
Assigned: | 2005-10-14 | ||||||||
Published: | 2005-10-14 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter. | ||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, 2005-05-21 19:15:11 Gallery 2.x Remote File Access Vulnerability Source: CCN Type: Gallery Download Web site Gallery2:Download - Gallery Codex Source: MITRE Type: CNA CVE-2005-3251 Source: MISC Type: Exploit, Vendor Advisory http://dipper.info/security/20051012/ Source: CCN Type: Gallery Web site Gallery - Your Photos on Your Website Source: CONFIRM Type: Patch http://gallery.menalto.com/gallery_2.0.1_released Source: CCN Type: SA17205 Gallery "g2_itemId" Disclosure of Sensitive Information Source: SECUNIA Type: UNKNOWN 17205 Source: SREASON Type: UNKNOWN 88 Source: CCN Type: OSVDB ID: 20017 Gallery main.php g2_itemId Parameter Traversal Arbitrary File Access Source: CCN Type: BID-15108 Gallery Main.PHP Directory Traversal Vulnerability Source: MISC Type: Vendor Advisory http://www.vuxml.org/freebsd/47bdabcf-3cf9-11da-baa2-0004614cc33d.html Source: XF Type: UNKNOWN gallery-dotdot-directory-traversal(22747) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |