CVE Vulnerabilities

CVE-2001-1234

Published: Oct 02, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.

Affected Software

NameVendorStart VersionEnd Version
GalleryGallery_project1.1 (including)1.1 (including)
GalleryGallery_project1.2 (including)1.2 (including)
GalleryGallery_project1.2.1 (including)1.2.1 (including)

References