CVE-2008-5296: Medium severity notfound gallery vulnerability
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when registerglobals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5296?
CVE-2008-5296 has a moderate severity rating as it allows bypassing authentication in certain configurations.
How do I fix CVE-2008-5296?
To fix CVE-2008-5296, upgrade Gallery to version 1.5.10 or later, or 1.6-RC3 or later.
What versions of Gallery are affected by CVE-2008-5296?
CVE-2008-5296 affects Gallery versions prior to 1.5.10 and 1.6 versions before 1.6-RC3.
Does enabling register_globals affect CVE-2008-5296?
Yes, enabling register_globals increases the vulnerability of CVE-2008-5296, making it easier for attackers to bypass authentication.
What type of attacks can occur due to CVE-2008-5296?
CVE-2008-5296 can lead to unauthorized administrative access due to authentication bypass via manipulated cookies.