CVE-2006-1219: Medium severity Gallery Project Gallery vulnerability
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1219?
CVE-2006-1219 is considered to have a high severity due to its potential for remote code execution through directory traversal.
How do I fix CVE-2006-1219?
To fix CVE-2006-1219, upgrade Gallery to version 2.0.4 or 2.1 RC-2a or later.
Which versions of Gallery are affected by CVE-2006-1219?
CVE-2006-1219 affects Gallery versions 2.0.3 and earlier, as well as all versions of 2.1 prior to RC-2a.
What types of attacks can CVE-2006-1219 enable?
CVE-2006-1219 can enable attackers to execute arbitrary PHP files on the server through directory traversal.
Who is primarily impacted by CVE-2006-1219?
Users and administrators of affected versions of Gallery who have not upgraded are primarily impacted by CVE-2006-1219.