Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-4129

Опубликовано: 18 сент. 2008
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.5.9-1.2ubuntu1
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

not-affected

1.5.9-1.2ubuntu1
karmic

not-affected

1.5.9-1.2ubuntu1
lucid

not-affected

1.5.9-1.2ubuntu1
maverick

not-affected

1.5.9-1.2ubuntu1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

2.2.6-1
feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

not-affected

2.2.6-1
jaunty

not-affected

2.2.6-1
karmic

not-affected

2.2.6-1
lucid

not-affected

2.2.6-1
maverick

not-affected

2.2.6-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 68%
0.00586
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

nvd
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

debian
почти 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle Z ...

github
больше 3 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.

EPSS

Процентиль: 68%
0.00586
Низкий

4 Medium

CVSS2