Vulnerabilities > CVE-2007-1108 - Remote File Include vulnerability in CS-Gallery

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
cs-gallery
exploit available

Summary

PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action.

Vulnerable Configurations

Part Description Count
Application
Cs-Gallery
1

Exploit-Db

descriptionCS-Gallery 2.0 (index.php album) Remote File Include Exploit. CVE-2007-1108. Webapps exploit for php platform
fileexploits/php/webapps/3372.php
idEDB-ID:3372
last seen2016-01-31
modified2007-02-24
platformphp
port
published2007-02-24
reporterburncycle
sourcehttps://www.exploit-db.com/download/3372/
titleCS-Gallery 2.0 index.php album Remote File Include Exploit
typewebapps