Skip to main content

Vendor archive

menalto CVEs

Beta · best-effort

23 CVEs tagged to vendor menalto7 Critical, 5 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2013-2241

Published Oct 10, 2013

modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2240

Published Oct 10, 2013

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a diffe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2138

Published Oct 10, 2013

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecifie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4343

Published Aug 15, 2012

Multiple unspecified vulnerabilities in Gallery 3 before 3.0.4 allow attackers to execute arbitrary PHP code via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4342

Published Aug 15, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2405

Published Apr 22, 2012

Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1113

Published Apr 22, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4353

Published Jan 25, 2011

Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execu…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3600

Published Aug 12, 2008

Directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1.5.7 and 1.6-alpha3, when register_globals is enabled, allows remote attackers to include and execute a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2720

Published Jun 16, 2008

Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2721

Published Jun 16, 2008

Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by attempting to add a new album to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2722

Published Jun 16, 2008

Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2723

Published Jun 16, 2008

embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2724

Published Jun 16, 2008

Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6685

Published Jan 17, 2008

Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6686

Published Jan 17, 2008

The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6687

Published Jan 17, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6688

Published Jan 17, 2008

Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the sto…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6689

Published Jan 17, 2008

Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core applicati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6690

Published Jan 17, 2008

The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6691

Published Jan 17, 2008

Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the W…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6692

Published Jan 17, 2008

Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6693

Published Jan 17, 2008

Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1