header-logo
Suggest Exploit
vendor:
phpAlbum
by:
SecurityFocus
7.5
CVSS
HIGH
Remote File Include
98
CWE
Product Name: phpAlbum
Affected Version From: 0.3.2.3
Affected Version To: Prior Versions
Patch Exists: YES
Related CWE: N/A
CPE: a:phpalbum:phpalbum
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005

phpAlbum Remote File Include Vulnerability

phpAlbum is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

Mitigation:

Input validation should be used to ensure that user-supplied data is properly sanitized.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/17526/info

phpAlbum is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access. 

phpAlbum 0.3.2.3 and prior versions are affected.

phpAlbum is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access. 

phpAlbum 0.3.2.3 and prior versions are affected.