First published: Mon Oct 17 2005(Updated: )
Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GalleryCMS | =2.0_alpha4 | |
GalleryCMS | =2.0_beta2 | |
GalleryCMS | =2.0_beta1 | |
GalleryCMS | =2.0_alpha2 | |
GalleryCMS | =2.0_alpha1 | |
GalleryCMS | =2.0_beta3 | |
GalleryCMS | =2.0 | |
GalleryCMS | =2.0_alpha3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3251 is considered a high severity vulnerability due to its potential for remote exploitation and unauthorized file access.
To fix CVE-2005-3251, upgrade to a patched version of Gallery, preferably version 2.0.1 or later.
CVE-2005-3251 affects Gallery versions 2.0, 2.0_alpha1, 2.0_alpha2, 2.0_alpha3, 2.0_alpha4, and 2.0_beta1 through 2.0_beta3.
CVE-2005-3251 is a directory traversal vulnerability that allows attackers to read or include arbitrary files.
Yes, CVE-2005-3251 can be exploited remotely by attackers through specially crafted requests.