PT-2005-3175 · Iphotoalbum · Photoalbum

Gold_M

·

Published

2005-07-12

·

Updated

2017-10-11

·

CVE-2005-2246

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: iPhotoAlbum version 1.1
Description: The issue allows remote attackers to execute arbitrary code. This is achieved via the doc path parameter to "getpage.php" or the set menu parameter to "lib/static/header.php".
Recommendations: For iPhotoAlbum version 1.1, consider restricting access to the "getpage.php" and "lib/static/header.php" files until a patch is available. Avoid using the doc path and set menu parameters in the affected API endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2246

Affected Products

Photoalbum