CVE-2006-1126: Medium severity Gallery Project Gallery vulnerability
Published Mar 9, 2006
·Updated
Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (XFORWARDEDFOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTEADDR.
Affected Software
1 affected component
Gallery Project Gallery=2.0.2
Remediation
Patch Available
Patch Available
Event History
Mar 9, 2006
CVE Published
10:02 PM
Mar 10, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1126?
CVE-2006-1126 is considered a mediumSeverity vulnerability as it allows attackers to spoof their IP addresses.
2
How do I fix CVE-2006-1126?
To fix CVE-2006-1126, upgrade Gallery to version 2.0.3 or later, which addresses this vulnerability.
3
What software is affected by CVE-2006-1126?
CVE-2006-1126 affects Gallery versions up to 2.0.2.
4
What types of attacks can CVE-2006-1126 lead to?
CVE-2006-1126 can lead to IP address spoofing attacks, allowing unauthorized access or manipulation of user sessions.
5
Is there a known exploit for CVE-2006-1126?
Yes, CVE-2006-1126 can be exploited by sending maliciously crafted HTTP requests with a spoofed X-Forwarded-For header.