upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
References
Link | Resource |
---|---|
http://marc.info/?l=vulnwatch&m=105128431109082&w=2 | |
http://secunia.com/advisories/8683 | Vendor Advisory |
http://marc.info/?l=vulnwatch&m=105128431109082&w=2 | |
http://secunia.com/advisories/8683 | Vendor Advisory |
Configurations
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=vulnwatch&m=105128431109082&w=2 - | |
References | () http://secunia.com/advisories/8683 - Vendor Advisory |
Information
Published : 2003-12-31 05:00
Updated : 2024-11-20 23:47
NVD link : CVE-2003-1489
Mitre link : CVE-2003-1489
CVE.ORG link : CVE-2003-1489
JSON object : View
Products Affected
truegalerie
- truegalerie
CWE
CWE-287
Improper Authentication