7.5
CVSSv2

CVE-2003-1227

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote malicious users to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 1.4_pl1

gallery project gallery 1.4

Exploits

source: wwwsecurityfocuscom/bid/8814/info It has been reported that Gallery is prone to a remote file include vulnerability in the indexphp script file The problem occurs due to the program failing to verify the location in which it includes the utilphp script, when handling specific requests to indexphp As a result, an attacker may ...