CVE-2006-1128: Medium severity Gallery Project Gallery vulnerability
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1128?
CVE-2006-1128 is considered to be a high severity vulnerability due to the potential for unauthorized file access and deletion.
How do I fix CVE-2006-1128?
To fix CVE-2006-1128, upgrade Gallery to version 2.0.3 or later which addresses this vulnerability.
What versions of Gallery are affected by CVE-2006-1128?
CVE-2006-1128 affects Gallery versions 2.0, 2.0.1, 2.0.2, and all alpha and beta versions up to 2.0.2.
What kind of attack can be performed using CVE-2006-1128?
An attacker can exploit CVE-2006-1128 to perform directory traversal attacks, gaining access to unauthorized files on the server.
Is user interaction required for CVE-2006-1128 to be exploited?
No, CVE-2006-1128 can be exploited remotely without user interaction through crafted requests.