Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gallery 会话处理类 目录遍历漏洞
Vulnerability Description
Gallery 2至2.0.2的会话处理类中存在目录遍历漏洞(GallerySession.class) ,远程攻击者可以通过在Cookie中指定会话,访问和删除文件,在会话值被清除前用于构建文件路径。
CVSS Information
N/A
Vulnerability Type
N/A