Vulnerabilities > CVE-2007-2068 - Remote File Include vulnerability in StoreFront for Gallery Gallery_BaseDir

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
storefront-for-gallery
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.

Vulnerable Configurations

Part Description Count
Application
Storefront_For_Gallery
1

Exploit-Db

descriptionStoreFront for Gallery (GALLERY_BASEDIR) RFI Vulnerabilities. CVE-2007-2068. Webapps exploit for php platform
fileexploits/php/webapps/3749.txt
idEDB-ID:3749
last seen2016-01-31
modified2007-04-16
platformphp
port
published2007-04-16
reporterAlkomandoz Hacker
sourcehttps://www.exploit-db.com/download/3749/
titleStoreFront for Gallery GALLERY_BASEDIR RFI Vulnerabilities
typewebapps