CVE-2001-1234: High severity Gallery Project Gallery vulnerability
Published Oct 2, 2001
·Updated
Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.
Affected Software
3 affected components
Gallery Project Gallery=1.1
Gallery Project Gallery=1.2
Gallery Project Gallery=1.2.1
Remediation
Patch Available
Event History
Oct 2, 2001
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1234?
CVE-2001-1234 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2001-1234?
To fix CVE-2001-1234, you should upgrade to Gallery version 1.2.1 or later, which patches this vulnerability.
3
What type of attack does CVE-2001-1234 allow?
CVE-2001-1234 allows remote attackers to execute arbitrary code by using a crafted HTTP request.
4
What software is affected by CVE-2001-1234?
CVE-2001-1234 affects Gallery versions 1.1, 1.2, and earlier than 1.2.1.
5
Is CVE-2001-1234 still relevant today?
While CVE-2001-1234 is an older vulnerability, it is important to patch affected versions to prevent exploitation in legacy systems.