The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/archive/1/418200/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/15614 - | |
References | () http://www.vupen.com/english/advisories/2005/2681 - |
Information
Published : 2005-12-05 11:03
Updated : 2025-04-03 01:03
NVD link : CVE-2005-4021
Mitre link : CVE-2005-4021
CVE.ORG link : CVE-2005-4021
JSON object : View
Products Affected
gallery_project
- gallery
CWE