Vulnerabilities > CVE-2007-6691 - Unspecified vulnerability in Menalto Gallery
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN menalto
nessus
Summary
Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the WebDAV module, (3) a comment view in the Comment module, (4) unspecified "item information disclosure attacks" in the Core module Gallery application, (5) the slideshow in the Slideshow module, and (6) multiple Print modules.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200802-04.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200802-04 (Gallery: Multiple vulnerabilities) The Gallery developement team reported and fixed critical vulnerabilities during an internal audit (CVE-2007-6685, CVE-2007-6686, CVE-2007-6687, CVE-2007-6688, CVE-2007-6689, CVE-2007-6690, CVE-2007-6691, CVE-2007-6692, CVE-2007-6693). Impact : A remote attacker could exploit these vulnerabilities to execute arbitrary code, conduct Cross-Site Scripting and Cross-Site Request Forgery attacks, or disclose sensitive informations. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31034 |
published | 2008-02-12 |
reporter | This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/31034 |
title | GLSA-200802-04 : Gallery: Multiple vulnerabilities |
code |
|
References
- http://bugs.gentoo.org/show_bug.cgi?id=203217
- http://bugs.gentoo.org/show_bug.cgi?id=203217
- http://gallery.menalto.com/gallery_2.2.4_released
- http://gallery.menalto.com/gallery_2.2.4_released
- http://osvdb.org/41662
- http://osvdb.org/41662
- http://osvdb.org/41663
- http://osvdb.org/41663
- http://osvdb.org/41664
- http://osvdb.org/41664
- http://osvdb.org/41665
- http://osvdb.org/41665
- http://osvdb.org/41666
- http://osvdb.org/41666
- http://osvdb.org/41667
- http://osvdb.org/41667
- http://secunia.com/advisories/28898
- http://secunia.com/advisories/28898
- http://security.gentoo.org/glsa/glsa-200802-04.xml
- http://security.gentoo.org/glsa/glsa-200802-04.xml