Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gallery HIGH 7.5
CVE-2013-2138

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote a…

Fix: after 3.0.7
Fix from $1,950 2013-10-10
Gallery HIGH 7.5
CVE-2013-2240

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impac…

Patch available
Fix from $1,950 2013-10-10
Gallery MEDIUM 5.0
CVE-2013-2241

modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive i…

Fix: after 3.0.8
Fix from $1,600 2013-10-10
Gallery HIGH 7.5
CVE-2012-4343

Multiple unspecified vulnerabilities in Gallery 3 before 3.0.4 allow attackers to execute arbitrary PHP code via unknown vectors.

Fix: after 3.0.3
Fix from $1,950 2012-08-15
Gallery MEDIUM 6.0
CVE-2010-4353

Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users wi…

Fix: after 2.2.6
Fix from $1,600 2011-01-25
Gallery MEDIUM 6.8
CVE-2008-3600

Directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1.5.7 and 1.6-alpha3, when register_globals is enabled, allows remote atta…

No fix yet
Fix from $1,600 2008-08-12
Gallery HIGH 7.5
CVE-2008-2722

Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive.

Fix: after 2.2.4
Fix from $1,950 2008-06-16
Gallery MEDIUM 5.0
CVE-2008-2721

Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by att…

Fix: after 2.2.4
Fix from $1,600 2008-06-16
Gallery MEDIUM 5.0
CVE-2008-2723

embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address…

Fix: after 2.2.4
Fix from $1,600 2008-06-16
Gallery MEDIUM 5.0
CVE-2008-2724

Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attack…

Mitigation only
Fix from $1,600 2008-06-16
Gallery Publish Xp Module HIGH 10.0
CVE-2007-6685

Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vector…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery HIGH 10.0
CVE-2007-6686

The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to t…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery HIGH 10.0
CVE-2007-6688

Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-acces…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery HIGH 10.0
CVE-2007-6690

The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery HIGH 10.0
CVE-2007-6691

Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite modu…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery Webcam Module HIGH 10.0
CVE-2007-6693

Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery HIGH 7.5
CVE-2007-6689

Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary c…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery MEDIUM 6.4
CVE-2007-6692

Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing att…

Fix: after 2.2.3
Fix from $1,600 2008-01-17