MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Minigal_2 | Thomas_rybak | 0.5.1 (including) | 0.5.1 (including) |
Minigal_2 | Thomas_rybak | b13 (including) | b13 (including) |