Korean
<< Back
VID 21412
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Gallery software, according to its version number, has a malicious PHP file uploading vulnerability.
Bharat Mediratta Gallery is a Web-based software product that lets you manage photos on any Web site that offers PHP support. Gallery 1.4.4-pl1 and earlier could allow a remote attacker to upload malicious PHP files, caused by a design error in the 'set_time_limit' function of the save_photos.php script. A remote attacker could exploit this vulnerability to execute commands on the vulnerable Web server.

* Note: This check solely relied on the version number of the remote Bharat Mediratta, Gallery program to assess this vulnerability, so this might be a false positive.

* References:
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0757.html
http://packetstormsecurity.nl/0408-exploits/gallery-php.txt

* Platforms Affected:
Bharat Mediratta, Gallery 1.4.4-pl1 and earlier
Linux Any version
Recommendation Upgrade to the latest version of Gallery (1.4.4-pl2 or later), available from the SourceForge Web site, Project: Gallery at http://sourceforge.net/projects/gallery

For Gentoo Linux:
Upgrade to the latest version of gallery (1.4.4_p2 or later), as listed in Gentoo Linux Security Advisory GLSA 200409-05 at http://www.gentoo.org/security/en/glsa/glsa-200409-05.xml
Related URL CVE-2004-1466 (CVE)
Related URL 10968 (SecurityFocus)
Related URL 17021 (ISS)