Back

CVE-2006-0587

Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file.

Published: Feb 8, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (16)

Vendor Product Version
gallery_project gallery 1.3.4
gallery_project gallery 1.4
gallery_project gallery 1.4.1
gallery_project gallery 1.4.2
gallery_project gallery 1.4.3_pl1
gallery_project gallery 1.4.3_pl2
gallery_project gallery 1.4.4_pl2
gallery_project gallery 1.4.4_pl3
gallery_project gallery 1.4.4_pl4
gallery_project gallery 1.4.4_pl5
gallery_project gallery 1.4_pl1
gallery_project gallery 1.4_pl2
gallery_project gallery 1.5
gallery_project gallery 1.5.1
gallery_project gallery 1.5.1_rc2
gallery_project gallery 1.5.2_rc2

GitHub Security Advisory GHSA-xm92-4w67-2rgg

Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated...

Risk Scores

CVSS Score 6.5 / 10
EPSS Score 2.74%

Top 15% most likely to be exploited

Threat Score 26.8 / 100

Data Sources

NVD EPSS GitHub