Vulnerabilities > CVE-2007-2068 - Remote File Include vulnerability in StoreFront for Gallery Gallery_BaseDir
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | StoreFront for Gallery (GALLERY_BASEDIR) RFI Vulnerabilities. CVE-2007-2068. Webapps exploit for php platform |
file | exploits/php/webapps/3749.txt |
id | EDB-ID:3749 |
last seen | 2016-01-31 |
modified | 2007-04-16 |
platform | php |
port | |
published | 2007-04-16 |
reporter | Alkomandoz Hacker |
source | https://www.exploit-db.com/download/3749/ |
title | StoreFront for Gallery GALLERY_BASEDIR RFI Vulnerabilities |
type | webapps |