PT-2007-3487 · Minigal · Minigal

Dj7Xpl

·

Published

2007-04-19

·

Updated

2017-10-11

·

CVE-2007-2145

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MiniGal version b13
Description The issue concerns the imagecomments function in classes.php, which allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter.
Recommendations For MiniGal version b13, consider restricting access to the vulnerable imagecomments function in classes.php until a patch is available. As a temporary workaround, avoid using the input parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2145

Affected Products

Minigal