CVE-2007-6689
Estado: ModificadaAlta (7.5)—
Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.01%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://bugs.gentoo.org/show_bug.cgi?id=203217
- http://gallery.menalto.com/gallery_2.2.4_released
- http://osvdb.org/41669
- http://secunia.com/advisories/28898
- http://security.gentoo.org/glsa/glsa-200802-04.xml
- http://bugs.gentoo.org/show_bug.cgi?id=203217
- http://gallery.menalto.com/gallery_2.2.4_released
- http://osvdb.org/41669
- http://secunia.com/advisories/28898
- http://security.gentoo.org/glsa/glsa-200802-04.xml
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-6689",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-01-17T02:00:00.000",
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=203217",
"source": "cve@mitre.org"
},
{
"url": "http://gallery.menalto.com/gallery_2.2.4_released",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/41669",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28898",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200802-04.xml",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=203217",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://gallery.menalto.com/gallery_2.2.4_released",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/41669",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28898",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200802-04.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module."
},
{
"lang": "es",
"value": "Menalto Gallery anterior a 2.2.4 no comprueba extensiones de fichero maliciosas durante la subida de ficheros, lo cual permite a atacantes remotos ejecutar código de su elección mediante los módulos (1) Core o (2) MIME."
}
],
"lastModified": "2026-06-16T22:48:34.843",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:menalto:gallery:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8783B6EF-0D51-4266-BE80-BCE62FAEB0C9",
"versionEndIncluding": "2.2.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}