5
CVSSv2

CVE-2006-1219

Published: 14/03/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in Gallery 2.0.3 and previous versions, and 2.1 before RC-2a, allows remote malicious users to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

gallery project gallery 2.0.3

gallery project gallery 2.0_alpha

gallery project gallery 2.0_beta3

gallery project gallery 2.1_rc1

gallery project gallery 2.0

gallery project gallery 2.0_alpha3

gallery project gallery 2.0_alpha4

gallery project gallery 2.0_alpha1

gallery project gallery 2.0_alpha2

gallery project gallery 2.1_rc2

gallery project gallery 2.0.1

gallery project gallery 2.0.2

gallery project gallery 2.0_beta1

gallery project gallery 2.0_beta2

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "Gallery <=203 \"stepOrder[]\" remote cmmnds xctn \r\n"; echo "by rgod rgod<AT>autistici<DOT>org \r\n"; echo "site: retrogodaltervistaorg \r\n\r\n"; echo "-> works with register_globals = ...