CVE-2012-4235: Infoleak
Published Aug 10, 2012
·Updated
The RSGallery2 (comrsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.
Affected Software
44 affected components
RSGallery2 Com Rsgallery2<=3.1.0
RSGallery2 Com Rsgallery2=1.9.0-4-alpha
RSGallery2 Com Rsgallery2=1.9.4-alpha
RSGallery2 Com Rsgallery2=1.9.5-alpha
RSGallery2 Com Rsgallery2=1.10.1-alpha
RSGallery2 Com Rsgallery2=1.10.2-alpha
RSGallery2 Com Rsgallery2=1.10.5-alpha
RSGallery2 Com Rsgallery2=1.10.6-alpha
RSGallery2 Com Rsgallery2=1.10.7-alpha
RSGallery2 Com Rsgallery2=1.10.8-alpha
RSGallery2 Com Rsgallery2=1.10.9-alpha
RSGallery2 Com Rsgallery2=1.10.10-alpha
RSGallery2 Com Rsgallery2=1.10.11-alpha
RSGallery2 Com Rsgallery2=1.10.13-alpha
RSGallery2 Com Rsgallery2=1.10.14-alpha
RSGallery2 Com Rsgallery2=1.11.0-alpha
RSGallery2 Com Rsgallery2=1.11.1-alpha
RSGallery2 Com Rsgallery2=1.11.2-alpha
RSGallery2 Com Rsgallery2=1.11.3-alpha
RSGallery2 Com Rsgallery2=1.11.4-alpha
RSGallery2 Com Rsgallery2=1.11.5-alpha
RSGallery2 Com Rsgallery2=1.11.6-alpha
RSGallery2 Com Rsgallery2=1.11.7-alpha
RSGallery2 Com Rsgallery2=1.11.8-alpha
RSGallery2 Com Rsgallery2=1.11.10-alpha
RSGallery2 Com Rsgallery2=1.11.11-alpha
RSGallery2 Com Rsgallery2=1.12.0-alpha
RSGallery2 Com Rsgallery2=1.12.1-alpha
RSGallery2 Com Rsgallery2=1.12.2-alpha
RSGallery2 Com Rsgallery2=1.13.0-alpha
RSGallery2 Com Rsgallery2=1.13.1-alpha
RSGallery2 Com Rsgallery2=1.14.0-alpha
RSGallery2 Com Rsgallery2=1.14.1-alpha
RSGallery2 Com Rsgallery2=2.1.0-beta
RSGallery2 Com Rsgallery2=2.1.1
RSGallery2 Com Rsgallery2=3.0-rc1
RSGallery2 Com Rsgallery2=3.0.1
Joomla Joomla\!=2.5.0
Joomla Joomla\!=2.5.1
Joomla Joomla\!=2.5.2
Joomla Joomla\!=2.5.3
Joomla Joomla\!=2.5.4
Joomla Joomla\!=2.5.5
Joomla Joomla\!=2.5.6
Remediation
Event History
Aug 10, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4235?
CVE-2012-4235 is considered a medium severity vulnerability as it allows remote attackers to list image filenames.
2
How do I fix CVE-2012-4235?
To fix CVE-2012-4235, you should upgrade the RSGallery2 component to version 3.2.0 or later.
3
Which versions are affected by CVE-2012-4235?
Versions of RSGallery2 prior to 3.2.0 are affected by CVE-2012-4235.
4
What type of vulnerability is CVE-2012-4235?
CVE-2012-4235 is a directory listing vulnerability that allows unauthorized access to image filenames.
5
Is CVE-2012-4235 exploitable remotely?
Yes, CVE-2012-4235 is exploitable remotely, allowing attackers to gain information about image files.