Unrated severityNVD Advisory· Published Mar 9, 2006· Updated Apr 16, 2026
CVE-2006-1126
CVE-2006-1126
Description
Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTE_ADDR.
Affected products
1- cpe:2.3:a:gallery_project:gallery:2.0.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- archives.neohapsis.com/archives/bugtraq/2006-02/0621.htmlnvdPatchVendor Advisory
- secunia.com/advisories/19104nvdPatchVendor Advisory
- securitytracker.com/idnvdPatchVendor Advisory
- www.gulftech.orgnvdPatch
- gallery.menalto.com/gallery_2.0.3_releasednvd
- www.vupen.com/english/advisories/2006/0813nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25120nvd
News mentions
0No linked articles in our index yet.