PT-2005-3175 · Iphotoalbum · Photoalbum
Gold_M
·
Published
2005-07-12
·
Updated
2017-10-11
·
CVE-2005-2246
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
iPhotoAlbum version 1.1
Description:
The issue allows remote attackers to execute arbitrary code. This is achieved via the
doc path parameter to "getpage.php" or the set menu parameter to "lib/static/header.php".Recommendations:
For iPhotoAlbum version 1.1, consider restricting access to the "getpage.php" and "lib/static/header.php" files until a patch is available. Avoid using the
doc path and set menu parameters in the affected API endpoints until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Photoalbum