modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2013-10-10 00:55
Updated : 2013-10-10 20:26
NVD link : CVE-2013-2241
Mitre link : CVE-2013-2241
CVE.ORG link : CVE-2013-2241
JSON object : View
Products Affected
menalto
- gallery
CWE
CWE-264
Permissions, Privileges, and Access Controls