CVE-2013-2240

Gallery 3 <3.0.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

References (5)

Core 5

Scores

EPSS 0.0069
EPSS Percentile 71.8%

Details

Status published
Products (9)
menalto/gallery 3.0
menalto/gallery 3.0.1
menalto/gallery 3.0.2
menalto/gallery 3.0.3
menalto/gallery 3.0.4
menalto/gallery 3.0.5
menalto/gallery 3.0.6
menalto/gallery 3.0.7
menalto/gallery 3.0.8
Published Oct 10, 2013
Tracked Since Feb 18, 2026