CVE Vulnerabilities

CVE-2007-0082

Published: Jan 05, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.

Affected Software

NameVendorStart VersionEnd Version
ImgalleryImgallery2.4 (including)2.4 (including)
ImgalleryImgallery2.5 (including)2.5 (including)

References