{"api_version":"1","generated_at":"2026-07-23T07:35:40+00:00","cve":"CVE-2007-4650","urls":{"html":"https://cve.report/CVE-2007-4650","api":"https://cve.report/api/cve/CVE-2007-4650.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4650","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4650"},"summary":{"title":"CVE-2007-4650","description":"Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using \"linked items\" in WebDAV and (b) Reupload modules.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-04 17:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://gallery.menalto.com/gallery_2.2.3_released","name":"http://gallery.menalto.com/gallery_2.2.3_released","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Gallery 2.2.3 Security Fix Release | Gallery","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2007/dsa-1404","name":"http://www.debian.org/security/2007/dsa-1404","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-1404-1 gallery2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25580","name":"http://www.securityfocus.com/bid/25580","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gallery Multiple Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=267421","name":"https://bugzilla.redhat.com/show_bug.cgi?id=267421","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 267421 – CVE-2007-4650 security update for gallery2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3072","name":"http://www.vupen.com/english/advisories/2007/3072","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.gentoo.org/show_bug.cgi?id=191587","name":"http://bugs.gentoo.org/show_bug.cgi?id=191587","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Bug 191587 - www-apps/gallery < 2.2.3 WebDAV and Reupload Module Data Manipulation Vulnerabilities (CVE-2007-4650)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/41658","name":"http://osvdb.org/41658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/27502","name":"http://secunia.com/advisories/27502","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo update for gallery - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200711-03.xml","name":"http://security.gentoo.org/glsa/glsa-200711-03.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Gallery: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html","name":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 7 Update: gallery2-2.2-0.7.svn20070831.fc7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27594","name":"http://secunia.com/advisories/27594","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian update for gallery2 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26716","name":"http://secunia.com/advisories/26716","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gallery WebDAV and Reupload Module Data Manipulation Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/41657","name":"http://osvdb.org/41657","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/26719","name":"http://secunia.com/advisories/26719","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fedora update for gallery2 - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4650","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4650","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4650","vulnerable":"1","versionEndIncluding":"2.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bharat_mediratta","cpe5":"gallery","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.902Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-200711-03","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200711-03.xml"},{"name":"26719","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26719"},{"name":"41657","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/41657"},{"name":"ADV-2007-3072","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3072"},{"name":"DSA-1404","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2007/dsa-1404"},{"name":"41658","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/41658"},{"name":"27594","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27594"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=267421"},{"name":"FEDORA-2007-2020","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html"},{"name":"25580","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25580"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://gallery.menalto.com/gallery_2.2.3_released"},{"name":"26716","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26716"},{"name":"27502","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27502"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=191587"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using \"linked items\" in WebDAV and (b) Reupload modules."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-07T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"GLSA-200711-03","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200711-03.xml"},{"name":"26719","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26719"},{"name":"41657","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/41657"},{"name":"ADV-2007-3072","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3072"},{"name":"DSA-1404","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2007/dsa-1404"},{"name":"41658","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/41658"},{"name":"27594","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27594"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=267421"},{"name":"FEDORA-2007-2020","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html"},{"name":"25580","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25580"},{"tags":["x_refsource_CONFIRM"],"url":"http://gallery.menalto.com/gallery_2.2.3_released"},{"name":"26716","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26716"},{"name":"27502","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27502"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=191587"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4650","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using \"linked items\" in WebDAV and (b) Reupload modules."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-200711-03","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200711-03.xml"},{"name":"26719","refsource":"SECUNIA","url":"http://secunia.com/advisories/26719"},{"name":"41657","refsource":"OSVDB","url":"http://osvdb.org/41657"},{"name":"ADV-2007-3072","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3072"},{"name":"DSA-1404","refsource":"DEBIAN","url":"http://www.debian.org/security/2007/dsa-1404"},{"name":"41658","refsource":"OSVDB","url":"http://osvdb.org/41658"},{"name":"27594","refsource":"SECUNIA","url":"http://secunia.com/advisories/27594"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=267421","refsource":"MISC","url":"https://bugzilla.redhat.com/show_bug.cgi?id=267421"},{"name":"FEDORA-2007-2020","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html"},{"name":"25580","refsource":"BID","url":"http://www.securityfocus.com/bid/25580"},{"name":"http://gallery.menalto.com/gallery_2.2.3_released","refsource":"CONFIRM","url":"http://gallery.menalto.com/gallery_2.2.3_released"},{"name":"26716","refsource":"SECUNIA","url":"http://secunia.com/advisories/26716"},{"name":"27502","refsource":"SECUNIA","url":"http://secunia.com/advisories/27502"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=191587","refsource":"CONFIRM","url":"http://bugs.gentoo.org/show_bug.cgi?id=191587"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4650","datePublished":"2007-09-04T17:00:00.000Z","dateReserved":"2007-09-04T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.902Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-04 17:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bharat_mediratta:gallery:*:*:*:*:*:*:*:*","versionEndIncluding":"2.2.2","matchCriteriaId":"27BE968E-DCFA-4453-B660-E793A7FB4CC7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4650","Ordinal":"1","Title":"CVE-2007-4650","CVE":"CVE-2007-4650","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4650","Ordinal":"1","NoteData":"Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using \"linked items\" in WebDAV and (b) Reupload modules.","Type":"Description","Title":"CVE-2007-4650"},{"CveYear":"2007","CveId":"4650","Ordinal":"2","NoteData":"2007-09-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4650","Ordinal":"3","NoteData":"2007-11-07","Type":"Other","Title":"Modified"}]}}}