Vulnerability Description
Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Menalto | Gallery | <= 2.2.6 |
References
- http://gallery.menalto.com/gallery_3.0.1_releasedPatchVendor Advisory
- http://osvdb.org/70628
- http://secunia.com/advisories/43028Vendor Advisory
- http://www.securityfocus.com/bid/45964Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64870
- http://gallery.menalto.com/gallery_3.0.1_releasedPatchVendor Advisory
- http://osvdb.org/70628
- http://secunia.com/advisories/43028Vendor Advisory
- http://www.securityfocus.com/bid/45964Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64870
FAQ
What is CVE-2010-4353?
CVE-2010-4353 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by ...
How severe is CVE-2010-4353?
CVE-2010-4353 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-4353?
Check the references section above for vendor advisories and patch information. Affected products include: Menalto Gallery.