Total vulnerabilities in the database
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used.
Software | From | Fixed in |
---|---|---|
invision_power_services / invision_gallery | 2.0.3 | 2.0.3.x |
invision_power_services / invision_gallery | 2.0.7 | 2.0.7.x |
invision_power_services / invision_gallery | 1.0.1 | 1.0.1.x |
invision_power_services / invision_gallery | 1.3 | 1.3.x |
invision_power_services / invision_gallery | 1.3.1 | 1.3.1.x |
invision_power_services / invision_gallery | 2.0.6 | 2.0.6.x |