AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2008-4129

MEDIUM · CVSS 4 EPSS 1.77%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-09-18 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2008-4129
Severity
MEDIUM
CVSS
4
EPSS
1.77%

Original Filing — NVD Description

Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.