Unrated severityNVD Advisory· Published Jan 25, 2011· Updated Apr 29, 2026
CVE-2010-4353
CVE-2010-4353
Description
Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
Affected products
12cpe:2.3:a:menalto:gallery:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:menalto:gallery:*:*:*:*:*:*:*:*range: <=2.2.6
- cpe:2.3:a:menalto:gallery:1.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:1.6:alpha3:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:menalto:gallery:2.2.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- gallery.menalto.com/gallery_3.0.1_releasednvdPatchVendor Advisory
- www.securityfocus.com/bid/45964nvdPatch
- secunia.com/advisories/43028nvdVendor Advisory
- osvdb.org/70628nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/64870nvd
News mentions
0No linked articles in our index yet.