shadlaws

1 exploit Active since Oct 2013
CVE-2013-2241 WRITEUP WRITEUP
Gallery < 3.0.9 - Information Disclosure via Size Parameter
modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.