Gallery Data Code Execution Vulnerability
BID:16533
Info
Gallery Data Code Execution Vulnerability
| Bugtraq ID: | 16533 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2006 12:00AM |
| Updated: | Feb 17 2006 06:42PM |
| Credit: | Discovery is credited to Tom Saville. |
| Vulnerable: |
Gallery Gallery 1.5.2 |
| Not Vulnerable: |
Gallery Gallery 1.5.2 -pl2 |
Discussion
Gallery Data Code Execution Vulnerability
Gallery is prone to an arbitrary code-execution vulnerability. This issue may allow a remote attacker to potentially execute commands on an affected computer.
A successful attack would lead to the execution of malicious code.
Gallery 1.5.2 is affected by this issue.
Gallery is prone to an arbitrary code-execution vulnerability. This issue may allow a remote attacker to potentially execute commands on an affected computer.
A successful attack would lead to the execution of malicious code.
Gallery 1.5.2 is affected by this issue.
Exploit / POC
Gallery Data Code Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gallery Data Code Execution Vulnerability
Solution:
The vendor has released Gallery version 1.5.2-pl2 to address this issue. Please see the reference section for further details.
Gallery Gallery 1.5.2
Solution:
The vendor has released Gallery version 1.5.2-pl2 to address this issue. Please see the reference section for further details.
Gallery Gallery 1.5.2
-
Gallery gallery-1.5.2-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.5.2-pl2.tar.gz
References
Gallery Data Code Execution Vulnerability
References:
References:
- Gallery 1.5.2-pl2 XSS Advisory (Gallery)
- Gallery Product Page (Gallery)
- Gallery web-based photo gallery remote file execution (Seregorn)
- Re: Digital Armaments Security Advisory 02.14.2006: Gallery web-based photo gall (Bharat Mediratta
)