|
Family: CGI abuses --> Category: attack
Gallery ZipCart File Retrieval Vulnerability Vulnerability Scan
Vulnerability Scan Summary Tries to retrieve a file using Gallery's ZipCart module
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application that is prone to an
information disclosure issue.
Description :
The remote host is running Gallery, a web-based photo album
application written in PHP.
The installation of Gallery on the remote host allows an
unauthenticated remote attacker to use the ZipCart module to retrieve
arbitrary files, subject to the rights of the web server user id.
See also :
http://archives.neohapsis.com/archives/bugtraq/2005-11/0371.html
Solution :
Deactivate the ZipCart module.
Threat Level:
Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:P/I:N/A:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|