CVE-2007-6689 Information

Description

Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module.

Reference

http://bugs.gentoo.org/show_bug.cgi?id=203217 http://gallery.menalto.com/gallery_2.2.4_released http://osvdb.org/41669 http://secunia.com/advisories/28898 http://security.gentoo.org/glsa/glsa-200802-04.xml

Share on: