|
|
Log in / Subscribe / Register

gallery: multiple vulnerabilities

Package(s):gallery CVE #(s):CVE-2008-3600 CVE-2008-3662 CVE-2008-4129 CVE-2008-4130
Created:November 12, 2008 Updated:December 15, 2008
Description:

From the Gentoo advisory:

* Digital Security Research Group reported a directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1, when register_globals is enabled (CVE-2008-3600).

* Hanno Boeck reported that Gallery 1 and 2 did not set the secure flag for the session cookie in an HTTPS session (CVE-2008-3662).

* Alex Ustinov reported that Gallery 1 and 2 does not properly handle ZIP archives containing symbolic links (CVE-2008-4129).

* The vendor reported a Cross-Site Scripting vulnerability in Gallery 2 (CVE-2008-4130).

Alerts:
Fedora FEDORA-2008-11218 gallery2 2008-12-13
Fedora FEDORA-2008-11258 gallery2 2008-12-13
Fedora FEDORA-2008-11230 gallery2 2008-12-13
Gentoo 200811-02 gallery 2008-11-09

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds