Back

CVE-2006-1128

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.

Published: Mar 9, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
gallery_project gallery 2.0
gallery_project gallery 2.0.1
gallery_project gallery 2.0.2
gallery_project gallery 2.0_alpha
gallery_project gallery 2.0_alpha1
gallery_project gallery 2.0_alpha2
gallery_project gallery 2.0_alpha3
gallery_project gallery 2.0_alpha4
gallery_project gallery 2.0_beta1
gallery_project gallery 2.0_beta2
gallery_project gallery 2.0_beta3

GitHub Security Advisory GHSA-w5x3-f77x-6rvv

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 3.92%

Top 10% most likely to be exploited

Threat Score 26.8 / 100

Data Sources

NVD EPSS GitHub