CVE-2010-4353
Published: 25 January 2011
Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
Priority
Status
Package | Release | Status |
---|---|---|
gallery Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(gallery 3 only)
|
hardy |
Not vulnerable
(gallery 3 only)
|
|
karmic |
Not vulnerable
(gallery 3 only)
|
|
lucid |
Not vulnerable
(gallery 3 only)
|
|
maverick |
Not vulnerable
(gallery 3 only)
|
|
upstream |
Not vulnerable
(gallery 3 only)
|
|
gallery2 Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(gallery 3 only)
|
hardy |
Not vulnerable
(gallery 3 only)
|
|
karmic |
Not vulnerable
(gallery 3 only)
|
|
lucid |
Not vulnerable
(gallery 3 only)
|
|
maverick |
Not vulnerable
(gallery 3 only)
|
|
upstream |
Released
(gallery 3.0.1)
|