CVE-2004-2124: Medium severity Gallery Project Gallery vulnerability
Published Dec 31, 2004
·Updated
The registerglobals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTPPOSTVARS variable and conduct a PHP remote file inclusion attack via the GALLERYBASEDIR parameter, a different vulnerability than CVE-2002-1412.
Affected Software
5 affected components
Gallery Project Gallery=1.3.1
Gallery Project Gallery=1.3.2
Gallery Project Gallery=1.3.3
Gallery Project Gallery=1.4
Gallery Project Gallery=1.4.1
Remediation
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2124?
CVE-2004-2124 is considered a high-severity vulnerability due to its potential for remote file inclusion attacks.
2
How do I fix CVE-2004-2124?
To fix CVE-2004-2124, upgrade to Gallery version 1.4.2 or later, which mitigates this vulnerability.
3
What software is affected by CVE-2004-2124?
CVE-2004-2124 affects Gallery versions 1.3.1 through 1.4.1.
4
What type of attack can be executed using CVE-2004-2124?
CVE-2004-2124 allows remote attackers to conduct PHP remote file inclusion attacks.
5
Is CVE-2004-2124 related to any other vulnerabilities?
CVE-2004-2124 is a different vulnerability than CVE-2002-1412, which has separate implications.