upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
References
Link | Resource |
---|---|
http://secunia.com/advisories/8683 | Vendor Advisory |
http://marc.info/?l=vulnwatch&m=105128431109082&w=2 |
Configurations
Information
Published : 2003-12-30 21:00
Updated : 2016-10-17 19:39
NVD link : CVE-2003-1489
Mitre link : CVE-2003-1489
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
truegalerie
- truegalerie