Gallery Prior to 2.2.6 Multiple Vulnerabilities
BID:31231
Info
Gallery Prior to 2.2.6 Multiple Vulnerabilities
| Bugtraq ID: | 31231 |
| Class: | Unknown |
| CVE: |
CVE-2008-3662 CVE-2008-4129 CVE-2008-4130 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2008 12:00AM |
| Updated: | Apr 13 2015 09:24PM |
| Credit: | Alex Ustinov, Hanno Boeck, Bharat Mediratta |
| Vulnerable: |
Gentoo Linux Bharat Mediratta Gallery 2.2.5 Bharat Mediratta Gallery 1.5.8 |
| Not Vulnerable: |
Bharat Mediratta Gallery 2.2.6 Bharat Mediratta Gallery 1.5.9 |
Discussion
Gallery Prior to 2.2.6 Multiple Vulnerabilities
Gallery is prone to multiple vulnerabilities, including a cross-site scripting issue, a cookie-disclosure weakness, and an information-disclosure issue.
An attacker may leverage these issues to obtain potentially sensitive information or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Gallery 2.2.6 and 1.5.9 are vulnerable.
Gallery is prone to multiple vulnerabilities, including a cross-site scripting issue, a cookie-disclosure weakness, and an information-disclosure issue.
An attacker may leverage these issues to obtain potentially sensitive information or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Gallery 2.2.6 and 1.5.9 are vulnerable.
Exploit / POC
Gallery Prior to 2.2.6 Multiple Vulnerabilities
Attackers can exploit the information-disclosure issue through a browser. To exploit the cross-site scripting issue, the attacker must entice unsuspecting users to follow a malicious URI. The attacker can exploit the cookie-disclosure weakness by using readily available network sniffers.
Attackers can exploit the information-disclosure issue through a browser. To exploit the cross-site scripting issue, the attacker must entice unsuspecting users to follow a malicious URI. The attacker can exploit the cookie-disclosure weakness by using readily available network sniffers.
Solution / Fix
Gallery Prior to 2.2.6 Multiple Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Gallery Prior to 2.2.6 Multiple Vulnerabilities
References:
References:
- Gallery 1.5.9 Security Fix Release (Bharat Mediratta)
- Gallery 2.2.6 Security Fix Release (Bharat Mediratta)
- Gallery Home Page (Bharat Mediratta)
- menalto gallery: Session hijacking vulnerability, CVE-2008-3662 (Hanno Boeck
)