CVE-2008-4129

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/09/2008
Last modified:
08/08/2017

Description

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gallery:gallery:*:*:*:*:*:*:*:* 2.2.5 (including)
cpe:2.3:a:gallery:gallery:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:gallery:gallery:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gallery:gallery:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gallery:gallery:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gallery:gallery:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gallery:gallery:*:*:*:*:*:*:*:* 1.5.8 (including)