Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via .. sequences in the g2_itemId parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gallery | Gallery_project | 2.0 (including) | 2.0 (including) |
Gallery | Gallery_project | 2.0_alpha1 (including) | 2.0_alpha1 (including) |
Gallery | Gallery_project | 2.0_alpha2 (including) | 2.0_alpha2 (including) |
Gallery | Gallery_project | 2.0_alpha3 (including) | 2.0_alpha3 (including) |
Gallery | Gallery_project | 2.0_alpha4 (including) | 2.0_alpha4 (including) |
Gallery | Gallery_project | 2.0_beta1 (including) | 2.0_beta1 (including) |
Gallery | Gallery_project | 2.0_beta2 (including) | 2.0_beta2 (including) |
Gallery | Gallery_project | 2.0_beta3 (including) | 2.0_beta3 (including) |