Korean
<< Back
VID 21688
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Gallery integrated with PostNuke, according to its version number, has an access validation vulnerability. Gallery is a Web-based photo album program written in PHP. Gallery versions prior to 1.5.1-RC2 could allow a remote attacker to bypass security restrictions. This security issue is caused due to incorrect use of the global "$name" variable to determine the gallery name in the "classes/postnuke0.7.1/User.php" script. This can be exploited by PostNuke users with any administrative privileges to bypass security restrictions and gain unauthorized access to other user's albums.

* Note: This check solely relied on the version number of Gallery on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://secunia.com/advisories/16389/
http://gallery.menalto.com/index.php?name=PNphpBB2&file=viewtopic&t=7048

* Platforms Affected:
Bharat Mediratta, Gallery prior to 1.5.1-RC2
Any operating system Any version
Recommendation Upgrade to the latest version of Gallery (1.5.1-RC2 or later), available from the Gallery Project Page Web site at http://gallery.menalto.com/index.php
Related URL CVE-2005-2596 (CVE)
Related URL 14547 (SecurityFocus)
Related URL 21771 (ISS)