PT-2025-32405 · Gallery · Gallery

Published

2025-08-08

·

Updated

2025-08-08

·

CVE-2012-10052

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: EGallery version 1.2
Description: EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application does not validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files directly into the web-accessible egallery/ directory, resulting in full remote code execution under the web server context.
Recommendations: Update to a newer version of EGallery that addresses this issue. As a temporary workaround, restrict access to the uploadify.php script. Implement strict file type validation on the server-side to prevent the upload of unauthorized file types.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2012-10052

Affected Products

Gallery