CVE-2006-1128

Gallery 2 up to 2.0.2 - Directory Traversal via Session Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1128.

AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in Gallery 2, including IP spoofing via X_FORWARDED_FOR, script injection, and arbitrary file access due to improper session handling. It includes code snippets and root cause analysis but does not contain functional exploit code.

Description

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/43837

This is a detailed technical analysis of multiple vulnerabilities in Gallery 2, including IP spoofing via X_FORWARDED_FOR, script injection, and arbitrary file access due to improper session handling. It includes code snippets and root cause analysis but does not contain functional exploit code.

Classification
Writeup 100%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Gallery 2 <= 2.0.2
No auth needed
Prerequisites: Access to the target web application · Ability to send crafted HTTP headers
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://gallery.menalto.com/gallery_2.0.3_released
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25118
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23597
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16948
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0813
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2006-02/0621.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19104
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015717

Scores

EPSS 0.0392
EPSS Percentile 89.0%

Details

Status published
Products (11)
gallery_project/gallery 2.0
gallery_project/gallery 2.0.1
gallery_project/gallery 2.0.2
gallery_project/gallery 2.0_alpha
gallery_project/gallery 2.0_alpha1
gallery_project/gallery 2.0_alpha2
gallery_project/gallery 2.0_alpha3
gallery_project/gallery 2.0_alpha4
gallery_project/gallery 2.0_beta1
gallery_project/gallery 2.0_beta2
... and 1 more
Published Mar 09, 2006
Tracked Since Feb 18, 2026