MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=113063215507210&w=2 | |
http://secunia.com/advisories/17374/ | Exploit Vendor Advisory |
http://securityreason.com/securityalert/128 | |
http://www.securityfocus.com/bid/15235 | Exploit |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-11-02T11:00:00
Updated: 2016-10-17T13:57:01
Reserved: 2005-11-02T00:00:00
Link: CVE-2005-3432
JSON object: View
NVD Information
Status : Modified
Published: 2005-11-02T11:02:00.000
Modified: 2016-10-18T03:35:34.633
Link: CVE-2005-3432
JSON object: View
Redhat Information
No data.
CWE