Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gallery ‘data_rest.php’多个信息泄露漏洞
Vulnerability Description
Gallery是美国软件开发者Bharat Mediratta所研发的一款基于Web的开源相册管理器。该管理器支持对相片自动生成缩略图、改变大小、排序等。 Gallery 3.0.9之前的3版本中的modules/gallery/helpers/data_rest.php文件中存在安全漏洞。远程攻击者可通过size参数中‘full’字符串利用该漏洞绕过既定的访问限制,获取图像文件的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A