漏洞信息详情
Gallery ‘User.php’ 访问验证漏洞
- CNNVD编号:CNNVD-200508-159
- 危害等级: 中危
- CVE编号:
CVE-2005-2596
- 漏洞类型:
访问验证错误
- 发布时间:
2005-08-17
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
gallery_project - 漏洞来源:
Discovery credited… -
漏洞简介
Gallery中的User.php页面,如同Postnuke中的一样,允许具有任何管理权限的用户访问所有的照片。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Gallery Gallery 1.4
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4 -pl2
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4 -pl1
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.1
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.2
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.3 -pl1
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.3 -pl2
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.4 -pl3
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.4 -pl2
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.4 -pl5
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.4.4 -pl4
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239&release_id=348064
Gallery Gallery 1.5
Debian gallery_1.5-1sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.5-1sarge1_all.deb
参考网址
来源: SECUNIA
名称: 16389
链接:http://secunia.com/advisories/16389
来源: BID
名称: 14547
链接:http://www.securityfocus.com/bid/14547
来源: DEBIAN
名称: DSA-879
链接:http://www.debian.org/security/2005/dsa-879
来源: SECUNIA
名称: 17367
链接:http://secunia.com/advisories/17367
来源: gallery.menalto.com
链接:http://gallery.menalto.com/index.php?name=PNphpBB2&file=viewtopic&t=7048