Vulnerabilities > CVE-2005-3432 - Authentication Bypass vulnerability in Thomas Rybak Minigal 2 0.5.1/B13

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
thomas-rybak
exploit available

Summary

MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.

Vulnerable Configurations

Part Description Count
Application
Thomas_Rybak
2

Exploit-Db

descriptionMG2 0.5.1 Authentication Bypass Vulnerability. CVE-2005-3432. Webapps exploit for php platform
idEDB-ID:26436
last seen2016-02-03
modified2005-10-29
published2005-10-29
reporterPreben Nylokken
sourcehttps://www.exploit-db.com/download/26436/
titleMG2 0.5.1 - Authentication Bypass Vulnerability