Back to Database
Status published
Critical
CVE-2012-2405
Gallery 2 before 2.3.2 and 3 before 3.0.3 does not...
Vulnerability Description
Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2405
Credits & Attribution
No credits recorded in the NVD database.
References
More from maian
View All →CVE-2012-1113
Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in...
Medium
4.3
CVE-2008-3322
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers...
High
7.5
CVE-2008-3320
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers...
High
7.5
CVE-2008-3319
admin/index.php in Maian Links 3.1 and earlier allows remote attackers...
High
7.5
CVE-2008-3318
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers...
High
7.5
Affected Vendor
maian
View all reports →Affected Software
gallery
Vulnerable Versions:
2.3, 2.3.1, 3.0, 3.0.1, 3.0.2, 2.2.6
Timeline
Official Publish:
April 22nd, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.