Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2004-2124

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.
0
Attacker Value
Unknown

CVE-2003-0614

Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.
0
Attacker Value
Unknown

CVE-2002-2130

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown

CVE-2002-2123

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter.
0