Back

CVE-2005-3251

Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.

Published: Oct 17, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (8)

Vendor Product Version
gallery_project gallery 2.0
gallery_project gallery 2.0_alpha1
gallery_project gallery 2.0_alpha2
gallery_project gallery 2.0_alpha3
gallery_project gallery 2.0_alpha4
gallery_project gallery 2.0_beta1
gallery_project gallery 2.0_beta2
gallery_project gallery 2.0_beta3

GitHub Security Advisory GHSA-r859-f8rq-g2xr

Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.90%

Top 22% most likely to be exploited

Threat Score 26.2 / 100

Data Sources

NVD EPSS GitHub