CVE-2005-3251

Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gallery_project:gallery:2.0:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha2:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha3:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_alpha4:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_beta1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_beta2:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:2.0_beta3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:01

Type Values Removed Values Added
References () http://dipper.info/security/20051012/ - Exploit, Vendor Advisory () http://dipper.info/security/20051012/ - Exploit, Vendor Advisory
References () http://gallery.menalto.com/gallery_2.0.1_released - Patch () http://gallery.menalto.com/gallery_2.0.1_released - Patch
References () http://secunia.com/advisories/17205 - () http://secunia.com/advisories/17205 -
References () http://securityreason.com/securityalert/88 - () http://securityreason.com/securityalert/88 -
References () http://www.vuxml.org/freebsd/47bdabcf-3cf9-11da-baa2-0004614cc33d.html - Vendor Advisory () http://www.vuxml.org/freebsd/47bdabcf-3cf9-11da-baa2-0004614cc33d.html - Vendor Advisory

Information

Published : 2005-10-17 20:06

Updated : 2025-04-03 01:03


NVD link : CVE-2005-3251

Mitre link : CVE-2005-3251

CVE.ORG link : CVE-2005-3251


JSON object : View

Products Affected

gallery_project

  • gallery