vendor:
Zenphoto Image Gallery
by:
Abysssec Inc
7,5
CVSS
HIGH
Command Execution
78
CWE
Product Name: Zenphoto Image Gallery
Affected Version From: Zenphoto <= 1.3
Affected Version To: Zenphoto <= 1.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:zenphoto:zenphoto
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
Unknown
Zenphoto Config Update and Command Execute Vulnerability
This exploit allows an attacker to reset the admin password of Zenphoto Image Gallery 1.3 by sending malicious POST requests to the setup.php file. The attacker can also upload malicious PHP files to the target server by editing the themes tab.
Mitigation:
Upgrade to the latest version of Zenphoto Image Gallery.