CVE-2003-1227

PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gallery_project:gallery:1.4_pl1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.4:*:*:*:*:*:*:*

Information

Published : 2003-12-30 21:00

Updated : 2017-07-10 18:29


NVD link : CVE-2003-1227

Mitre link : CVE-2003-1227


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

gallery_project

  • gallery