PT-2002-2843 · Gallery · Gallery
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-2123
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Gallery version 1.3.2
Description:
The issue allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the
GALLERY BASEDIR parameter. This is related to a remote file inclusion vulnerability in the publish xp docs.php file.Recommendations:
For Gallery version 1.3.2, avoid using the
GALLERY BASEDIR parameter with external URLs until a patch is available. As a temporary workaround, consider restricting access to the publish xp docs.php file to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gallery