Vulnerabilities > Menalto > Gallery > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-10-10 CVE-2013-2241 Permissions, Privileges, and Access Controls vulnerability in Menalto Gallery
modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
network
low complexity
menalto CWE-264
5.0
2012-08-15 CVE-2012-4342 Cross-Site Scripting vulnerability in Menalto Gallery
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
menalto CWE-79
4.3
2012-04-22 CVE-2012-1113 Cross-Site Scripting vulnerability in multiple products
Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
maian menalto CWE-79
4.3
2011-01-25 CVE-2010-4353 Unspecified vulnerability in Menalto Gallery
Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
network
menalto
6.0
2008-08-12 CVE-2008-3600 Path Traversal vulnerability in Menalto Gallery 1.5.7/1.6
Directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1.5.7 and 1.6-alpha3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..
network
menalto CWE-22
6.8
2008-06-16 CVE-2008-2724 Permissions, Privileges, and Access Controls vulnerability in Menalto Gallery
Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.
network
low complexity
menalto CWE-264
5.0
2008-06-16 CVE-2008-2723 Information Exposure vulnerability in Menalto Gallery
embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."
network
low complexity
menalto CWE-200
5.0
2008-06-16 CVE-2008-2721 Information Exposure vulnerability in Menalto Gallery
Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by attempting to add a new album to a hidden album.
network
low complexity
menalto CWE-200
5.0
2008-06-16 CVE-2008-2720 Cross-Site Scripting vulnerability in Menalto Gallery
Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL.
network
menalto CWE-79
4.3
2008-01-17 CVE-2007-6692 Link Following vulnerability in Menalto Gallery
Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.
network
low complexity
menalto CWE-59
6.4