CVE-2004-2124

The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gallery_project:gallery:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.4:*:*:*:*:*:*:*

Information

Published : 2004-12-30 21:00

Updated : 2017-07-10 18:31


NVD link : CVE-2004-2124

Mitre link : CVE-2004-2124


JSON object : View

Advertisement

dedicated server usa

Products Affected

gallery_project

  • gallery