CVE-2009-1446

Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elkagroup:image_gallery:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-04-27 19:30

Updated : 2024-02-04 17:33


NVD link : CVE-2009-1446

Mitre link : CVE-2009-1446

CVE.ORG link : CVE-2009-1446


JSON object : View

Products Affected

elkagroup

  • image_gallery
CWE
CWE-20

Improper Input Validation