Where
-Infinity
0
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when registerglobals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."

First published (updated )
Severity
4
XSS

It was reported [1] that some low-risk XSS flaws that are limited to the administration area were found in Gallery 3.x and 2.x. In addition, some unspecified possible encryption-related flaws were also reported. These issues have been corrected in Gallery 2.3.2 and 3.0.3.

[1] http://gallery.menalto.com/gallery303andgallery232

First published (updated )
Severity
4
Path Traversal
AV:N/AC:L/Au:S/C:P/I:N/A:N

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

First published (updated )
Severity
1

Multiple information exposure flaws were found in the way data rest core module of Gallery version 3, an open source project with the goal to develop and support leading photo sharing web application solutions, used to previously restrict access to certain items of the photo album. A remote attacker, valid Gallery 3 user, could use this flaw to possibly obtain sensitive information (file, resize or thumb path of the item in question).

References: [1] http://galleryproject.org/gallery309

Upstream ticket: [2] http://sourceforge.net/apps/trac/gallery/ticket/2074

Relevant upstream patch (against 3.0.x branch): [3] https://github.com/gallery/gallery3/commit/cbbcf1b4791762d7da0ea7b6c4f4b551a4d9caed

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203