Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65hm-pfc7-5f2p

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

EPSS

Процентиль: 68%
0.00586
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

redhat
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

nvd
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

debian
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle Z ...

EPSS

Процентиль: 68%
0.00586
Низкий

Дефекты

CWE-22