main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to users, as demonstrated via index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gallery | Crux_software | * | 1.32 (including) |
Gallery | Crux_software | 1.0 (including) | 1.0 (including) |
Gallery | Crux_software | 1.1 (including) | 1.1 (including) |
Gallery | Crux_software | 1.2 (including) | 1.2 (including) |
Gallery | Crux_software | 1.30 (including) | 1.30 (including) |
Gallery | Crux_software | 1.31 (including) | 1.31 (including) |
Gallery | Crux_software | 1.32 (including) | 1.32 (including) |