PT-2007-5329 · Rig · Ralf Image Gallery
Published
2007-08-01
·
Updated
2024-08-07
·
CVE-2007-4127
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ralf Image Gallery (RIG) version 1.0
Description
A remote file inclusion issue exists, allowing remote attackers to execute arbitrary PHP code via a URL in the
dir abs src parameter in the check entry.php file. However, it is reported that the product exits if register globals is enabled, potentially blocking exploitation.Recommendations
For Ralf Image Gallery (RIG) version 1.0, consider disabling the check entry.php file or restricting access to it until a fix is available. Additionally, ensure that register globals is disabled to prevent potential exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ralf Image Gallery