|
Family: CGI abuses --> Category: attack
gallery code injection (3) Vulnerability Scan
Vulnerability Scan Summary Searches for the existence of init.php
Detailed Explanation for this Vulnerability Test
It is possible to make the remote host include php files hosted
on a third party server using Gallery.
A possible hacker may use this flaw to inject arbitrary code in the remote
host and gain a shell with the rights of the web server.
Solution : Upgrade to Gallery 1.4.1 pl1 or newer
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|