CVE-2013-2138

Menalto Gallery < 3.0.7 - Improper Input Validation

Title source: rule
STIX 2.1

Description

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

Scores

EPSS 0.0121
EPSS Percentile 79.1%

Details

CWE
CWE-20
Status published
Products (8)
menalto/gallery 3.0 (6 CPE variants)
menalto/gallery 3.0.1
menalto/gallery 3.0.2
menalto/gallery 3.0.3
menalto/gallery 3.0.4
menalto/gallery 3.0.5
menalto/gallery 3.0.6
menalto/gallery < 3.0.7
Published Oct 10, 2013
Tracked Since Feb 18, 2026