PT-2003-2172 · Gallery · Gallery
Publicado
2003-12-31
·
Atualizado
2017-07-11
·
CVE-2003-1227
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gallery versions 1.4 through 1.4-pl1
Description
A remote file include issue exists in index.php, allowing remote attackers to inject arbitrary PHP code via a URL in the
GALLERY BASEDIR parameter. This issue might be exploitable only during installation or if the administrator has not run a security script after installation.Recommendations
For Gallery versions 1.4 through 1.4-pl1, consider running the security script provided after installation to mitigate the risk of exploitation. As a temporary workaround, restrict access to the
GALLERY BASEDIR parameter to minimize the risk of arbitrary PHP code injection.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gallery