First published: Mon Dec 01 2008(Updated: )
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Gallery | <=1.5.9 | |
NotFound Gallery | <=1.6 | |
NotFound Gallery | =1.2.1 | |
NotFound Gallery | =1.3.1 | |
NotFound Gallery | =1.3.2 | |
NotFound Gallery | =1.3.3 | |
NotFound Gallery | =1.3.4-pl1 | |
NotFound Gallery | =1.4 | |
NotFound Gallery | =1.4.1 | |
NotFound Gallery | =1.4.4 | |
NotFound Gallery | =1.4.4-pl2 | |
NotFound Gallery | =1.5.1-rc2 | |
NotFound Gallery | =1.5.2 | |
NotFound Gallery | =1.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5296 has a moderate severity rating as it allows bypassing authentication in certain configurations.
To fix CVE-2008-5296, upgrade Gallery to version 1.5.10 or later, or 1.6-RC3 or later.
CVE-2008-5296 affects Gallery versions prior to 1.5.10 and 1.6 versions before 1.6-RC3.
Yes, enabling register_globals increases the vulnerability of CVE-2008-5296, making it easier for attackers to bypass authentication.
CVE-2008-5296 can lead to unauthorized administrative access due to authentication bypass via manipulated cookies.