Vulnerabilities > CVE-2002-1412 - Unspecified vulnerability in Gallery Project Gallery
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | Bharat Mediratta Gallery 1.x Remote File Include Vulnerability. CVE-2002-1412. Webapps exploit for php platform |
id | EDB-ID:21676 |
last seen | 2016-02-02 |
modified | 2002-08-01 |
published | 2002-08-01 |
reporter | PowerTech |
source | https://www.exploit-db.com/download/21676/ |
title | Bharat Mediratta Gallery 1.x - Remote File Include Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-138.NASL |
description | A problem was found in gallery (a web-based photo album toolkit): it was possible to pass in the GALLERY_BASEDIR variable remotely. This made it possible to execute commands under the uid of web-server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14975 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14975 |
title | Debian DSA-138-1 : gallery - remote exploit |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0471.html
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0471.html
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=50&mode=thread&order=0&thold=0
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=50&mode=thread&order=0&thold=0
- http://www.debian.org/security/2002/dsa-138
- http://www.debian.org/security/2002/dsa-138
- http://www.securityfocus.com/bid/5375
- http://www.securityfocus.com/bid/5375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9737
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9737