Page 15 of 72 results (0.006 seconds)

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 1

Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter. • https://www.exploit-db.com/exploits/21157 http://marc.info/?l=bugtraq&m=100619599000590&w=2 http://www.menalto.com/projects/gallery/article.php?sid=33&mode=&order= http://www.osvdb.org/677 http://www.securityfocus.com/bid/3554 https://exchange.xforce.ibmcloud.com/vulnerabilities/7580 •

CVSS: 7.5EPSS: 2%CPEs: 3EXPL: 1

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable. • http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html http://prdownloads.sourceforge.net/gallery/gallery-1.2.5.tar.gz http://www.iss.net/security_center/static/7215.php http://www.osvdb.org/1967 http://www.securityfocus.com/bid/3397 •