Vulnerabilities > CVE-2004-2124 - Remote Global Variable Injection vulnerability in Gallery

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
gallery-project
nessus
exploit available

Summary

The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.

Exploit-Db

descriptionGallery 1.3.x/1.4 Remote Global Variable Injection Vulnerability. CVE-2004-2124 . Webapps exploit for php platform
idEDB-ID:23599
last seen2016-02-02
modified2004-01-26
published2004-01-26
reporterBharat Mediratta
sourcehttps://www.exploit-db.com/download/23599/
titleGallery 1.3.x/1.4 - Remote Global Variable Injection Vulnerability

Nessus

  • NASL familyCGI abuses
    NASL idGALLERY_INJECTION3.NASL
    descriptionIt is possible to make the remote host include PHP files hosted on a third-party server using the version of Gallery installed on the remote host. An attacker may use this flaw to inject arbitrary code in the remote host and gain a shell with the privileges of the web server.
    last seen2020-06-01
    modified2020-06-02
    plugin id12030
    published2004-01-29
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12030
    titleGallery HTTP Global Variables File Inclusion
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_12B1A62D60564D909E2145FCDE6ABAE4.NASL
    descriptionA web server running Gallery can be exploited for arbitrary PHP code execution through the use of a maliciously crafted URL.
    last seen2020-06-01
    modified2020-06-02
    plugin id18846
    published2005-07-13
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/18846
    titleFreeBSD : gallery -- remote code injection via HTTP_POST_VARS (12b1a62d-6056-4d90-9e21-45fcde6abae4)