Secunia Logo
 
CVE Reference: CVE-2007-6689
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-6689

Description:
Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA28898

OSVDB
  41669

GENTOO
  http://security.gentoo.org/glsa/glsa-200802-04.xml

CONFIRM
  http://bugs.gentoo.org/show_bug.cgi?id=203217
  http://gallery.menalto.com/gallery_2.2.4_released


Return to the previous page.