vendor:
Gallery
by:
SecurityFocus
7.5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: Gallery
Affected Version From: Gallery 1.3.2
Affected Version To: Gallery 1.3.2
Patch Exists: YES
Related CWE: N/A
CPE: a:gallery:gallery:1.3.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Gallery Remote File Include Vulnerability
It has been reported that Gallery is prone to a remote file include vulnerability in the index.php script file. The problem occurs due to the program failing to verify the location in which it includes the util.php script, when handling specific requests to index.php. As a result, an attacker may be capable of having arbitrary PHP script code being executed on the remote host with the privileges of the web server.
Mitigation:
Input validation should be used to ensure that user-supplied data is not used to include files from external sources.