PT-2003-2172 · Gallery · Gallery
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1227
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gallery versions 1.4 through 1.4-pl1
Description
A remote file include issue exists in index.php, allowing remote attackers to inject arbitrary PHP code via a URL in the
GALLERY BASEDIR parameter. This issue might be exploitable only during installation or if the administrator has not run a security script after installation.Recommendations
For Gallery versions 1.4 through 1.4-pl1, consider running the security script provided after installation to mitigate the risk of exploitation. As a temporary workaround, restrict access to the
GALLERY BASEDIR parameter to minimize the risk of arbitrary PHP code injection.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gallery