lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.
https://bugzilla.redhat.com/show_bug.cgi?id=981197
http://www.openwall.com/lists/oss-security/2013/07/04/11