Skip to main content

Vendor archive

gallery CVEs

Beta · best-effort

4 CVEs tagged to vendor gallery0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2008-5296

Published Dec 1, 2008

Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cook…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4130

Published Sep 18, 2008

Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4129

Published Sep 18, 2008

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3662

Published Sep 18, 2008

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and mak…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1