Gallery Configuration Mode Authentication Bypass (deprecated)

high Nessus Network Monitor Plugin ID 2500

Synopsis

The remote host is vulnerable to a flaw that allows for the bypassing of authentication.

Description

The remote server is running Gallery in configuration mode. Gallery is a software tool for webservers that allows for easy creation of online photo albums. This version of Gallery has been installed but not yet configured. Any remote user discovering the configuration screen may be able to modify web content on the remote server.

Solution

Configure Gallery, then disable configuration mode.

Plugin Details

Severity: High

ID: 2500

Family: Web Servers

Published: 8/18/2004

Updated: 1/15/2016