CVE Vulnerabilities

CVE-2013-2240

Published: Oct 10, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

Affected Software

Name Vendor Start Version End Version
Gallery Menalto 3.0 (including) 3.0 (including)
Gallery Menalto 3.0.1 (including) 3.0.1 (including)
Gallery Menalto 3.0.2 (including) 3.0.2 (including)
Gallery Menalto 3.0.3 (including) 3.0.3 (including)
Gallery Menalto 3.0.4 (including) 3.0.4 (including)
Gallery Menalto 3.0.5 (including) 3.0.5 (including)
Gallery Menalto 3.0.6 (including) 3.0.6 (including)
Gallery Menalto 3.0.7 (including) 3.0.7 (including)
Gallery Menalto 3.0.8 (including) 3.0.8 (including)

References