|
Message-ID: <Pine.GSO.4.51.0806161830460.16840@faron.mitre.org> Date: Mon, 16 Jun 2008 18:30:56 -0400 (EDT) From: "Steven M. Christey" <coley@...us.mitre.org> To: Hanno Böck <hanno@...eck.de> cc: oss-security@...ts.openwall.com, coley@...re.org Subject: Re: CVE id request: menalto gallery ====================================================== Name: CVE-2008-2720 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2720 Reference: CONFIRM:http://gallery.menalto.com/gallery_2.2.5_released Reference: SECUNIA:30650 Reference: URL:http://secunia.com/advisories/30650 Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL. ====================================================== Name: CVE-2008-2721 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2721 Reference: CONFIRM:http://gallery.menalto.com/gallery_2.2.5_released Reference: SECUNIA:30650 Reference: URL:http://secunia.com/advisories/30650 Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by attempting to add a new album to a hidden album. ====================================================== Name: CVE-2008-2722 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2722 Reference: CONFIRM:http://gallery.menalto.com/gallery_2.2.5_released Reference: SECUNIA:30650 Reference: URL:http://secunia.com/advisories/30650 Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive. ====================================================== Name: CVE-2008-2723 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2723 Reference: CONFIRM:http://gallery.menalto.com/gallery_2.2.5_released Reference: SECUNIA:30650 Reference: URL:http://secunia.com/advisories/30650 embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address." ====================================================== Name: CVE-2008-2724 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2724 Reference: CONFIRM:http://gallery.menalto.com/gallery_2.2.5_released Reference: SECUNIA:30650 Reference: URL:http://secunia.com/advisories/30650 Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.