Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-4650 | First vendor Publication | 2007-09-04 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4650 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:18693 | |||
Oval ID: | oval:org.mitre.oval:def:18693 | ||
Title: | DSA-1404-1 gallery2 - privilege escalation | ||
Description: | Nicklous Roberts discovered that the Reupload module of Gallery 2, a web based photo management application, allowed unauthorised users to edit Gallery's data file. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1404-1 CVE-2007-4650 | Version: | 7 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | gallery2 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-02-27 | Name : Fedora Update for gallery2 FEDORA-2007-2020 File : nvt/gb_fedora_2007_2020_gallery2_fc7.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200711-03 (gallery) File : nvt/glsa_200711_03.nasl |
2008-09-04 | Name : FreeBSD Ports: gallery2 File : nvt/freebsd_gallery20.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1404-1 (gallery2) File : nvt/deb_1404_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
41658 | Gallery Reupload Module Linked Item Unspecified File Manipulation |
41657 | Gallery WebDAV Module Unspecified File Manipulation |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-11-12 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_9b718b828ef511dc8e42001c2514716c.nasl - Type : ACT_GATHER_INFO |
2007-11-09 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1404.nasl - Type : ACT_GATHER_INFO |
2007-11-06 | Name : The remote Fedora host is missing a security update. File : fedora_2007-2020.nasl - Type : ACT_GATHER_INFO |
2007-11-02 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200711-03.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:16:24 |
|
2024-11-28 12:13:22 |
|
2021-05-04 12:06:20 |
|
2021-04-22 01:06:53 |
|
2020-05-23 01:38:42 |
|
2020-05-23 00:20:23 |
|
2016-06-28 16:52:39 |
|
2016-04-26 16:33:14 |
|
2014-02-17 10:41:32 |
|
2013-05-11 10:35:19 |
|