| Title |
Gallery Prior to 2.2.6 Multiple Vulnerabilities |
| Published |
2008-09-18-12:00AM |
| Updated |
2008-09-18-06:10PM |
| Class |
Unknown |
| CVE |
CVE-2008-3662 |
| Remote |
Yes |
| Local |
No |
| Credit |
Alex Ustinov, Hanno Boeck, Bharat Mediratta |
| Vulnerable |
Bharat Mediratta Gallery 2.2.5 Bharat Mediratta Gallery 1.5.8
|
| Not Vulnerable |
Bharat Mediratta Gallery 2.2.6 Bharat Mediratta Gallery 1.5.9
|
| Code |
Attackers can exploit the information-disclosure issue through a browser. To exploit the cross-site scripting issue, the attacker must entice unsuspecting users to follow a malicious URI. The attacker can exploit the cookie-disclosure weakness by using readily available network sniffers. |
| TXT |
 |