CVE-2002-1412: High severity Gallery Project Gallery vulnerability
Published Apr 11, 2003
·Updated
Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERYBASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.
Affected Software
1 affected component
Gallery Project Gallery<=1.3.1
Remediation
Patch Available
Event History
Apr 11, 2003
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1412?
CVE-2002-1412 has a moderate severity rating due to its potential to allow attackers to execute arbitrary code.
2
How do I fix CVE-2002-1412?
To fix CVE-2002-1412, update the Gallery package to version 1.3.1 or later.
3
What software is affected by CVE-2002-1412?
CVE-2002-1412 affects Gallery photo album packages prior to version 1.3.1.
4
What does CVE-2002-1412 exploit?
CVE-2002-1412 exploits a vulnerability in the handling of the GALLERY_BASEDIR variable.
5
Can CVE-2002-1412 be exploited remotely?
Yes, CVE-2002-1412 can potentially be exploited by remote attackers if the conditions are met.