CVE-2007-4650
Summary
| CVE | CVE-2007-4650 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-04 17:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
Problem Types: CWE-264 | NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bharat Mediratta | Gallery | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gallery 2.2.3 Security Fix Release | Gallery | af854a3a-2127-422b-91ae-364da2661108 | gallery.menalto.com | Patch |
| Debian -- Security Information -- DSA-1404-1 gallery2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Gallery Multiple Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug 267421 – CVE-2007-4650 security update for gallery2 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Bug 191587 - www-apps/gallery < 2.2.3 WebDAV and Reupload Module Data Manipulation Vulnerabilities (CVE-2007-4650) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| osvdb.org/41658 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo update for gallery - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- Gallery: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [SECURITY] Fedora 7 Update: gallery2-2.2-0.7.svn20070831.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for gallery2 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gallery WebDAV and Reupload Module Data Manipulation Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/41657 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Fedora update for gallery2 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.