vendor:
Truegalerie
by:
SecurityFocus
7.5
CVSS
HIGH
Unauthorized Administrative Access
79
CWE
Product Name: Truegalerie
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE: CVE-2002-1490
CPE: o:truegalerie:truegalerie:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002
Unauthorized Administrative Access
Truegalerie is vulnerable to an unauthorized administrative access vulnerability due to insufficient sanitization of some URI values. By sending a specially crafted HTTP request, an attacker can gain administrative access to the application.
Mitigation:
Upgrade to the latest version of Truegalerie.