First published: Fri Aug 10 2012(Updated: )
The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSGallery2 | <=3.1.0 | |
RSGallery2 | =1.9.0-4-alpha | |
RSGallery2 | =1.9.4-alpha | |
RSGallery2 | =1.9.5-alpha | |
RSGallery2 | =1.10.1-alpha | |
RSGallery2 | =1.10.2-alpha | |
RSGallery2 | =1.10.5-alpha | |
RSGallery2 | =1.10.6-alpha | |
RSGallery2 | =1.10.7-alpha | |
RSGallery2 | =1.10.8-alpha | |
RSGallery2 | =1.10.9-alpha | |
RSGallery2 | =1.10.10-alpha | |
RSGallery2 | =1.10.11-alpha | |
RSGallery2 | =1.10.13-alpha | |
RSGallery2 | =1.10.14-alpha | |
RSGallery2 | =1.11.0-alpha | |
RSGallery2 | =1.11.1-alpha | |
RSGallery2 | =1.11.2-alpha | |
RSGallery2 | =1.11.3-alpha | |
RSGallery2 | =1.11.4-alpha | |
RSGallery2 | =1.11.5-alpha | |
RSGallery2 | =1.11.6-alpha | |
RSGallery2 | =1.11.7-alpha | |
RSGallery2 | =1.11.8-alpha | |
RSGallery2 | =1.11.10-alpha | |
RSGallery2 | =1.11.11-alpha | |
RSGallery2 | =1.12.0-alpha | |
RSGallery2 | =1.12.1-alpha | |
RSGallery2 | =1.12.2-alpha | |
RSGallery2 | =1.13.0-alpha | |
RSGallery2 | =1.13.1-alpha | |
RSGallery2 | =1.14.0-alpha | |
RSGallery2 | =1.14.1-alpha | |
RSGallery2 | =2.1.0-beta | |
RSGallery2 | =2.1.1 | |
RSGallery2 | =3.0-rc1 | |
RSGallery2 | =3.0.1 | |
Joomla | =2.5.0 | |
Joomla | =2.5.1 | |
Joomla | =2.5.2 | |
Joomla | =2.5.3 | |
Joomla | =2.5.4 | |
Joomla | =2.5.5 | |
Joomla | =2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4235 is considered a medium severity vulnerability as it allows remote attackers to list image filenames.
To fix CVE-2012-4235, you should upgrade the RSGallery2 component to version 3.2.0 or later.
Versions of RSGallery2 prior to 3.2.0 are affected by CVE-2012-4235.
CVE-2012-4235 is a directory listing vulnerability that allows unauthorized access to image filenames.
Yes, CVE-2012-4235 is exploitable remotely, allowing attackers to gain information about image files.