Vulnerability Description
User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.
CVSS Score
4.6
MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gallery Project | Gallery | 1.3.4 |
References
- http://gallery.menalto.com/index.php?name=PNphpBB2&file=viewtopic&t=7048
- http://secunia.com/advisories/16389PatchVendor Advisory
- http://secunia.com/advisories/17367
- http://www.debian.org/security/2005/dsa-879
- http://www.securityfocus.com/bid/14547
- http://gallery.menalto.com/index.php?name=PNphpBB2&file=viewtopic&t=7048
- http://secunia.com/advisories/16389PatchVendor Advisory
- http://secunia.com/advisories/17367
- http://www.debian.org/security/2005/dsa-879
- http://www.securityfocus.com/bid/14547
FAQ
What is CVE-2005-2596?
CVE-2005-2596 is a vulnerability with a CVSS score of 4.6 (MEDIUM). User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.
How severe is CVE-2005-2596?
CVE-2005-2596 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2596?
Check the references section above for vendor advisories and patch information. Affected products include: Gallery Project Gallery.