First published: Tue Dec 31 2002(Updated: )
PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gallery Project Gallery | =1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2123 is considered a high severity vulnerability due to its potential for arbitrary code execution by remote attackers.
To mitigate CVE-2002-2123, upgrade to a patched version of Gallery beyond 1.3.2 where the vulnerability is resolved.
CVE-2002-2123 is a remote file inclusion vulnerability that allows attackers to inject arbitrary PHP code.
CVE-2002-2123 specifically affects Gallery version 1.3.2.
Yes, CVE-2002-2123 can be exploited remotely without the need for authentication.