
CVE-2002-1412 – Bharat Mediratta Gallery 1.x - Remote File Inclusion
https://notcve.org/view.php?id=CVE-2002-1412
11 Apr 2003 — Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script. El paquete album de fotos Gallery anterior a 1.3.1permite a atacantes locales y posiblemente remotos ejecutar código arbitrario mediante una variable GALLERY_BASEDIR que apunta a un directorio o una URL que contiene un script php.ini que sea caballo de Troya. • https://www.exploit-db.com/exploits/21676 •

CVE-2002-2123
https://notcve.org/view.php?id=CVE-2002-2123
31 Dec 2002 — PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter. • http://www.securityfocus.com/archive/1/304611 •

CVE-2002-2130
https://notcve.org/view.php?id=CVE-2002-2130
31 Dec 2002 — publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code. • http://archives.neohapsis.com/archives/bugtraq/2002-12/0260.html •

CVE-2001-0900 – bharat Mediratta Gallery 1.1/1.2 - Directory Traversal
https://notcve.org/view.php?id=CVE-2001-0900
18 Nov 2001 — Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter. • https://www.exploit-db.com/exploits/21157 •

CVE-2001-1234
https://notcve.org/view.php?id=CVE-2001-1234
02 Oct 2001 — Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable. • http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html •