6.4

CVE-2006-1128

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.

Data is provided by the National Vulnerability Database (NVD)
Gallery ProjectGallery Version2.0
Gallery ProjectGallery Version2.0.1
Gallery ProjectGallery Version2.0.2
Gallery ProjectGallery Version2.0_alpha
Gallery ProjectGallery Version2.0_alpha1
Gallery ProjectGallery Version2.0_alpha2
Gallery ProjectGallery Version2.0_alpha3
Gallery ProjectGallery Version2.0_alpha4
Gallery ProjectGallery Version2.0_beta1
Gallery ProjectGallery Version2.0_beta2
Gallery ProjectGallery Version2.0_beta3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.7% 0.926
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N