CVE Vulnerabilities

CVE-2013-2240

Published: Oct 10, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

Affected Software

NameVendorStart VersionEnd Version
GalleryMenalto3.0 (including)3.0 (including)
GalleryMenalto3.0.1 (including)3.0.1 (including)
GalleryMenalto3.0.2 (including)3.0.2 (including)
GalleryMenalto3.0.3 (including)3.0.3 (including)
GalleryMenalto3.0.4 (including)3.0.4 (including)
GalleryMenalto3.0.5 (including)3.0.5 (including)
GalleryMenalto3.0.6 (including)3.0.6 (including)
GalleryMenalto3.0.7 (including)3.0.7 (including)
GalleryMenalto3.0.8 (including)3.0.8 (including)

References