MooseGallery Display.PHP File Include Vulnerability
BID:14280
Info
MooseGallery Display.PHP File Include Vulnerability
| Bugtraq ID: | 14280 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2005 12:00AM |
| Updated: | Jul 15 2005 12:00AM |
| Credit: | Credit is given to ][GB][ for the discovery of this vulnerability. |
| Vulnerable: |
MooseGallery MooseGallery 1.0.2 MooseGallery MooseGallery 1.0.1 |
| Not Vulnerable: | |
Discussion
MooseGallery Display.PHP File Include Vulnerability
MooseGallery is susceptible to a remote PHP file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
MooseGallery is susceptible to a remote PHP file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
MooseGallery Display.PHP File Include Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
MooseGallery Display.PHP File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MooseGallery Display.PHP File Include Vulnerability
References:
References:
- MooseGallery Web Site (MooseGallery)