CVE-2007-4650
Estado: ModificadaMedia (6.4)—
Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.70%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264, NVD-CWE-noinfo
Referencias
- http://bugs.gentoo.org/show_bug.cgi?id=191587
- http://gallery.menalto.com/gallery_2.2.3_released
- http://osvdb.org/41657
- http://osvdb.org/41658
- http://secunia.com/advisories/26716
- http://secunia.com/advisories/26719
- http://secunia.com/advisories/27502
- http://secunia.com/advisories/27594
- http://security.gentoo.org/glsa/glsa-200711-03.xml
- http://www.debian.org/security/2007/dsa-1404
- http://www.securityfocus.com/bid/25580
- http://www.vupen.com/english/advisories/2007/3072
- https://bugzilla.redhat.com/show_bug.cgi?id=267421
- https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html
- http://bugs.gentoo.org/show_bug.cgi?id=191587
- http://gallery.menalto.com/gallery_2.2.3_released
- http://osvdb.org/41657
- http://osvdb.org/41658
- http://secunia.com/advisories/26716
- http://secunia.com/advisories/26719
- http://secunia.com/advisories/27502
- http://secunia.com/advisories/27594
- http://security.gentoo.org/glsa/glsa-200711-03.xml
- http://www.debian.org/security/2007/dsa-1404
- http://www.securityfocus.com/bid/25580
- http://www.vupen.com/english/advisories/2007/3072
- https://bugzilla.redhat.com/show_bug.cgi?id=267421
- https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4650",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-09-04T17:17:00.000",
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=191587",
"source": "cve@mitre.org"
},
{
"url": "http://gallery.menalto.com/gallery_2.2.3_released",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/41657",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/41658",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26716",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26719",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27502",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27594",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200711-03.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2007/dsa-1404",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25580",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3072",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=267421",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=191587",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://gallery.menalto.com/gallery_2.2.3_released",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/41657",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/41658",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26716",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26719",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/27502",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/27594",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200711-03.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2007/dsa-1404",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25580",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3072",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=267421",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00097.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
},
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using \"linked items\" in WebDAV and (b) Reupload modules."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades no especificadas en Gallery anterior a 2.2.3 permite a atacantes (1) renombrar artículos, (2) leer y modificar propiedades de artículos, o (3) ver y reemplazar artículos mediante vectores no especificados en (a) el módulo WebDAV; y (4) editar información de ficheros no especificados utilizando \"artículos enlazados\" en WebDAV y (b) módulos Reupload."
}
],
"lastModified": "2026-06-16T22:44:30.383",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bharat_mediratta:gallery:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27BE968E-DCFA-4453-B660-E793A7FB4CC7",
"versionEndIncluding": "2.2.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}