CVE-2004-2124
published 2004-12-31CVE-2004-2124: The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
7.35%
93.6th percentile
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gallery_project | gallery | — | — |
| gallery_project | gallery | — | — |
| gallery_project | gallery | — | — |
| gallery_project | gallery | — | — |
| gallery_project | gallery | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://gallery.menalto.com/modules.php?op=modload&name=News&file=indexhttp://marc.info/?l=bugtraq&m=107524414317693&w=2http://secunia.com/advisories/10712/http://www.gentoo.org/security/en/glsa/glsa-200402-04.xmlhttp://www.osvdb.org/3737http://www.securityfocus.com/bid/9490https://exchange.xforce.ibmcloud.com/vulnerabilities/14950http://gallery.menalto.com/modules.php?op=modload&name=News&file=indexhttp://marc.info/?l=bugtraq&m=107524414317693&w=2http://secunia.com/advisories/10712/http://www.gentoo.org/security/en/glsa/glsa-200402-04.xmlhttp://www.osvdb.org/3737http://www.securityfocus.com/bid/9490https://exchange.xforce.ibmcloud.com/vulnerabilities/14950
2004-12-31
Published