← Back

CVE-2013-2138

nvd nist
Published: Oct 10, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

Affected (13)

Products: Menalto: Gallery
1 product
Gallery
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Menalto
Up to 3.0.7
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0
Version 3.0 beta1
Version 3.0 beta2
Version 3.0 beta3
Version 3.0 rc1
Version 3.0 rc2

Timeline

No history available yet.