CVE Vulnerabilities

CVE-2013-2240

Published: Oct 10, 2013 | Modified: Oct 10, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

Affected Software

Name Vendor Start Version End Version
Gallery Menalto 3.0 3.0
Gallery Menalto 3.0.1 3.0.1
Gallery Menalto 3.0.2 3.0.2
Gallery Menalto 3.0.3 3.0.3
Gallery Menalto 3.0.4 3.0.4
Gallery Menalto 3.0.5 3.0.5
Gallery Menalto 3.0.6 3.0.6
Gallery Menalto 3.0.7 3.0.7
Gallery Menalto 3.0.8 3.0.8

References