|
|
IMGallery "users_adm/start1.php" Extension Handling Arbitrary File Upload Vulnerability
|
A vulnerability has been identified in IMGallery, which could be exploited by remote attackers to bypass security restrictions and compromise a vulnerable web server. This issue is due to an input validation error in the "users_adm/start1.php" script when handling a file with multiple file extensions, which could be exploited by remote attackers to upload malicious PHP scripts and execute arbitrary commands on a vulnerable web server.
IMGallery version 2.5 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2007/0010
Vulnerability reported by Kacper
2007-01-02 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|