Vulnerabilities > CVE-2007-4127 - Unspecified vulnerability in LE Ralf Image Gallery 1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN le-ralf
exploit available
Summary
PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if register_globals is enabled, thereby blocking exploitation. NOTE: CVE-2006-3210.a covers this issue in versions before 1.0
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Ralf Image Gallery <= 0.7.4 Multiple Remote Vulnerabilities. CVE-2006-3210,CVE-2007-4127. Webapps exploit for php platform |
id | EDB-ID:1942 |
last seen | 2016-01-31 |
modified | 2006-06-22 |
published | 2006-06-22 |
reporter | Aesthetico |
source | https://www.exploit-db.com/download/1942/ |
title | ralf image gallery <= 0.7.4 - Multiple Vulnerabilities |
References
- http://www.attrition.org/pipermail/vim/2007-July/001743.html
- http://www.attrition.org/pipermail/vim/2007-July/001747.html
- http://www.attrition.org/pipermail/vim/2007-July/001749.html
- http://www.attrition.org/pipermail/vim/2007-July/001748.html
- http://securityreason.com/securityalert/2938
- http://osvdb.org/46973
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35689
- http://www.securityfocus.com/archive/1/475094/100/0/threaded