modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-10-09 17:55
Updated : 2013-10-10 13:26
NVD link : CVE-2013-2241
Mitre link : CVE-2013-2241
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
menalto
- gallery