5

CVE-2006-1219

Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.

Data is provided by the National Vulnerability Database (NVD)
Gallery ProjectGallery Version2.0
Gallery ProjectGallery Version2.0.1
Gallery ProjectGallery Version2.0.2
Gallery ProjectGallery Version2.0.3
Gallery ProjectGallery Version2.0_alpha
Gallery ProjectGallery Version2.0_alpha1
Gallery ProjectGallery Version2.0_alpha2
Gallery ProjectGallery Version2.0_alpha3
Gallery ProjectGallery Version2.0_alpha4
Gallery ProjectGallery Version2.0_beta1
Gallery ProjectGallery Version2.0_beta2
Gallery ProjectGallery Version2.0_beta3
Gallery ProjectGallery Version2.1_rc1
Gallery ProjectGallery Version2.1_rc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.28% 0.928
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N