5
CVE-2013-2241
- EPSS 1.57%
- Veröffentlicht 10.10.2013 00:55:14
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.57% | 0.721 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://galleryproject.org/gallery_3_0_9
http://www.openwall.com/lists/oss-security/2013/07/04/11
http://sourceforge.net/apps/trac/gallery/ticket/2074
http://www.openwall.com/lists/oss-security/2013/07/05/3
https://bugzilla.redhat.com/show_bug.cgi?id=981198
https://github.com/gallery/gallery3/commit/cbbcf1b4791762d7da0ea7b6c4f4b551a4d9caed