Vulnerability Name: | CVE-2004-2124 (CCN-14950) | ||||||||
Assigned: | 2004-01-26 | ||||||||
Published: | 2004-01-26 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-2124 Source: CCN Type: Gallery Web site Gallery :: your photos on your website Source: CONFIRM Type: Patch http://gallery.menalto.com/modules.php?op=modload&name=News&file=index Source: BUGTRAQ Type: UNKNOWN 20040127 Remote exploit in Gallery 1.3.1, 1.3.2, 1.3.3, 1.4 and 1.4.1 Source: CCN Type: SA10712 Gallery Arbitrary File Inclusion Vulnerability Source: SECUNIA Type: UNKNOWN 10712 Source: GENTOO Type: UNKNOWN GLSA-200402-04 Source: CCN Type: Gentoo Linux Security Announcement 200402-04 Gallery <= 1.4.1 remote exploit vulnerability Source: OSVDB Type: UNKNOWN 3737 Source: CCN Type: OSVDB ID: 3737 Gallery HTTP Global Variables File Inclusion Source: BID Type: UNKNOWN 9490 Source: CCN Type: BID-9490 Gallery Remote Global Variable Injection Vulnerability Source: XF Type: UNKNOWN gallery-gallerybasedir-file-include(14950) Source: XF Type: UNKNOWN gallery-gallerybasedir-file-include(14950) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |