MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Minigal_2 | Thomas_rybak | b13 | b13 |
Minigal_2 | Thomas_rybak | 0.5.1 | 0.5.1 |