6.8
CVSSv2

CVE-2008-4483

Published: 08/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in Crux Gallery 1.32 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

crux software gallery 1.31

crux software gallery 1.30

crux software gallery 1.0

crux software gallery 1.2

crux software gallery 1.1

crux software gallery

crux software gallery 1.32

Exploits

~~+=========================================================+~~ ~~+=========================================================+~~ [?] Crux Gallery <= 132 Local File Inclusion Vulnerability [?] Discovered On: 01/10/2008 [*] PHPini [*] Magic_Quotes_Gpc = Off ~~+=========================================================+~~ (indexphp) ...