Skip to content
Noroxi

gallery records

4 published records for vendor gallery.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

4 records
  • CVE-2008-5296
    27Monitor

    Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and g

    MediumCVSS 6.8No exploitEPSS 1%

    gallery · galleryDec 1, 2008

  • CVE-2008-3662
    21Monitor

    Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the coo

    MediumCVSS 5.0No exploitEPSS 2%

    gallery · gallerySep 18, 2008

  • CVE-2008-4129
    17Monitor

    Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticat

    MediumCVSS 4.0No exploitEPSS 2%

    gallery · gallerySep 18, 2008

  • CVE-2008-4130
    17Monitor

    Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web script or HTML via a cr

    MediumCVSS 4.3No exploitEPSS 2%

    gallery · gallerySep 18, 2008