Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4353

Опубликовано: 25 янв. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6

Описание

Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

РелизСтатусПримечание
dapper

not-affected

gallery 3 only
devel

not-affected

gallery 3 only
hardy

not-affected

gallery 3 only
karmic

not-affected

gallery 3 only
lucid

not-affected

gallery 3 only
maverick

not-affected

gallery 3 only
upstream

not-affected

gallery 3 only

Показывать по

РелизСтатусПримечание
dapper

not-affected

gallery 3 only
devel

not-affected

gallery 3 only
hardy

not-affected

gallery 3 only
karmic

not-affected

gallery 3 only
lucid

not-affected

gallery 3 only
maverick

not-affected

gallery 3 only
upstream

released

gallery 3.0.1

Показывать по

Ссылки на источники

EPSS

Процентиль: 78%
0.01187
Низкий

6 Medium

CVSS2

Связанные уязвимости

nvd
около 15 лет назад

Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

debian
около 15 лет назад

Unrestricted file upload vulnerability in modules/gallery/models/item. ...

github
больше 3 лет назад

Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

EPSS

Процентиль: 78%
0.01187
Низкий

6 Medium

CVSS2