VYPR
Vendor

Menalto

Products
3
CVEs
31
Across products
33
Status
Private

Products

3

Recent CVEs

31
View all 31 CVEs →
  • CVE-2001-0900Nov 18, 2001
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter.

  • CVE-2006-1127Mar 9, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.

  • CVE-2006-1128Mar 9, 2006
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is…

  • CVE-2003-0614Aug 27, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.

  • CVE-2013-2241Oct 10, 2013
    risk 0.00cvss epss 0.02

    modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.

  • CVE-2013-2240Oct 10, 2013
    risk 0.00cvss epss 0.02

    lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

  • CVE-2013-2138Oct 10, 2013
    risk 0.00cvss epss 0.03

    The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

  • CVE-2012-4343Aug 15, 2012
    risk 0.00cvss epss 0.01

    Multiple unspecified vulnerabilities in Gallery 3 before 3.0.4 allow attackers to execute arbitrary PHP code via unknown vectors.

  • CVE-2012-4342Aug 15, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2012-2405Apr 22, 2012
    risk 0.00cvss epss 0.01

    Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.

  • CVE-2012-1113Apr 22, 2012
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-4353Jan 25, 2011
    risk 0.00cvss epss 0.02

    Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…

  • CVE-2008-4130Sep 18, 2008
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted Flash animation, related to the ability of the animation to "interact with the embedding page."

  • CVE-2008-3600Aug 12, 2008
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1.5.7 and 1.6-alpha3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter within a modload action.

  • CVE-2008-2724Jun 16, 2008
    risk 0.00cvss epss 0.02

    Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.

  • CVE-2008-2722Jun 16, 2008
    risk 0.00cvss epss 0.02

    Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive.

  • CVE-2008-2721Jun 16, 2008
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by attempting to add a new album to a hidden album.

  • CVE-2008-2723Jun 16, 2008
    risk 0.00cvss epss 0.02

    embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."

  • CVE-2008-2720Jun 16, 2008
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL.

  • CVE-2007-6685Jan 17, 2008
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.