Vulnerabilities > CVE-2006-4030 - Unspecified vulnerability in Gallery Project Gallery
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN gallery-project
nessus
Summary
Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "two file exposure bugs."
Vulnerable Configurations
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1148.NASL |
description | Several remote vulnerabilities have been discovered in gallery, a web-based photo album. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2005-2734 A cross-site scripting vulnerability allows injection of web script code through HTML or EXIF information. - CVE-2006-0330 A cross-site scripting vulnerability in the user registration allows injection of web script code. - CVE-2006-4030 Missing input sanitising in the stats modules allows information disclosure. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22690 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22690 |
title | Debian DSA-1148-1 : gallery - several vulnerabilities |
code |
|
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285
- http://secunia.com/advisories/16594
- http://secunia.com/advisories/16594
- http://secunia.com/advisories/21502
- http://secunia.com/advisories/21502
- http://www.debian.org/security/2006/dsa-1148
- http://www.debian.org/security/2006/dsa-1148
- http://www.securityfocus.com/bid/19453
- http://www.securityfocus.com/bid/19453
- http://www.vupen.com/english/advisories/2006/3250
- http://www.vupen.com/english/advisories/2006/3250