CVE-2012-4235

medium
Published 2012-08-10 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
rsgallery2com_rsgallery2{"endIncluding":"3.1.0"}
rsgallery2com_rsgallery21.9.0-4
rsgallery2com_rsgallery21.9.4
rsgallery2com_rsgallery21.9.5
rsgallery2com_rsgallery21.10.1
rsgallery2com_rsgallery21.10.2
rsgallery2com_rsgallery21.10.5
rsgallery2com_rsgallery21.10.6
rsgallery2com_rsgallery21.10.7
rsgallery2com_rsgallery21.10.8
rsgallery2com_rsgallery21.10.9
rsgallery2com_rsgallery21.10.10
rsgallery2com_rsgallery21.10.11
rsgallery2com_rsgallery21.10.13
rsgallery2com_rsgallery21.10.14
rsgallery2com_rsgallery21.11.0
rsgallery2com_rsgallery21.11.1
rsgallery2com_rsgallery21.11.2
rsgallery2com_rsgallery21.11.3
rsgallery2com_rsgallery21.11.4
rsgallery2com_rsgallery21.11.5
rsgallery2com_rsgallery21.11.6
rsgallery2com_rsgallery21.11.7
rsgallery2com_rsgallery21.11.8
rsgallery2com_rsgallery21.11.10
rsgallery2com_rsgallery21.11.11
rsgallery2com_rsgallery21.12.0
rsgallery2com_rsgallery21.12.1
rsgallery2com_rsgallery21.12.2
rsgallery2com_rsgallery21.13.0
rsgallery2com_rsgallery21.13.1
rsgallery2com_rsgallery21.14.0
rsgallery2com_rsgallery21.14.1
rsgallery2com_rsgallery22.1.0
rsgallery2com_rsgallery22.1.1
rsgallery2com_rsgallery23.0
rsgallery2com_rsgallery23.0.1
joomla joomlajoomla\!2.5.0
joomla joomlajoomla\!2.5.1
joomla joomlajoomla\!2.5.2
joomla joomlajoomla\!2.5.3
joomla joomlajoomla\!2.5.4
joomla joomlajoomla\!2.5.5
joomla joomlajoomla\!2.5.6

References

CWEs

CWE-200

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.