PT-2007-3418 · Maian · Maian Gallery
K4Rtal
·
Published
2007-04-18
·
Updated
2018-10-16
·
CVE-2007-2076
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Maian Gallery version 1.0
Description
A remote file inclusion issue in index.php allows remote attackers to execute arbitrary PHP code via a URL in the
path to folder parameter. This issue was disputed by a third-party researcher but confirmed by the vendor.Recommendations
For Maian Gallery version 1.0, update to a version where this issue has been resolved, as the vendor confirmed the problem existed only briefly in this version.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maian Gallery