Pages: [1]
|
 |
|
Author
|
Topic: PhotoGal "news_file" Remote PHP File Inclusion Vulnerability (Read 488 times)
|
|
Brad
|
* Technical Description * A vulnerability was identified in PhotoGal, which may be exploited by attackers to compromise a vulnerable web server. This flaw is due to an input validation error in "gals.php" when processing a specially crafted "news_file" parameter, which may be exploited by remote attackers to include malicious files and execute arbitrary commands with the privileges of the web server. * Affected Products * PhotoGal version 1.5 and prior * Solution * No official supplied patch for this issue. * References * http://www.frsirt.com/english/advisories/2005/1037
|
|
|
|
|
Logged
|
|
|
|
|
Pages: [1]
|
|
|
 |