Korean
<< Back
VID 21268
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The My_eGallery PostNuke module is vulnerable to a remote execution vulnerability. A PostNuke module, My_eGallery allows users to create and manipulate their own galleries on the web, plus offers various additional features. Any version of My_eGallery, prior to 3.1.1.g, is susceptible to this vulnerability. An attacker can craft PHP code on their Web site and supply parameter to My_eGallery so it actually includes malicious PHP code. This allows execution of any command on the server with My_eGallery, under the privileges of the Web server (usually apache or httpd).

* Note: This check solely relied on the version number of the remote My_eGallery module to assess this vulnerability, so this might be a false positive.

* References:
http://www.securityfocus.com/archive/1/345790

* Platforms Affected:
My_eGallery 3.1.1g prior
Recommendation Apply the appropriate fix for your system or upgrade to the latest version (3.1.1.g or later) of My_eGallery, available from Sourceforge Web site at http://lottasophie.sourceforge.net/modules.php?op=modload&name=Downloads&file=index&req=viewdownload&cid=5
Related URL (CVE)
Related URL 9113 (SecurityFocus)
Related URL (ISS)