|
Family: CGI abuses --> Category: attack
Gallery g2_itemId Parameter Directory Traversal Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for g2_itemId parameter Directory Traversal vulnerability in Gallery
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is affected by a
directory traversal flaw.
Description :
The version of Gallery installed on the remote host fails to sanitize
user-supplied input to the 'g2_itemId' parameter of the 'main.php'
script before using it to read cached files. If PHP's
'display_errors' setting is enabled, a possible hacker can exploit this flaw
to read arbitrary files on the remote host, subject to the rights
of the web user id. Moreover, if the attacker can upload files to the
affected host, he may be able to execute arbitrary PHP code, again
subject to the rights of the web user id.
See also :
http://www.securityfocus.com/archive/1/413405
Solution :
Upgrade to Gallery 2.0.1 or later.
Threat Level:
Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:C)
Click HERE for more information and discussions on this network vulnerability scan.
|