Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations.
References
Configurations
History
21 Nov 2024, 00:22
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.shaftnet.org/task/113 - | |
References | () http://po.shaftnet.org/po_stable_changelog - Patch | |
References | () http://secunia.com/advisories/23176 - | |
References | () http://www.securityfocus.com/bid/21351 - Patch | |
References | () http://www.vupen.com/english/advisories/2006/4766 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30577 - |
Information
Published : 2006-12-04 11:28
Updated : 2025-04-09 00:30
NVD link : CVE-2006-6246
Mitre link : CVE-2006-6246
CVE.ORG link : CVE-2006-6246
JSON object : View
Products Affected
photo_organizer
- photo_organizer
CWE