The registerglobals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTPPOSTVARS variable and conduct a PHP remote file inclusion attack via the GALLERYBASEDIR parameter, a different vulnerability than CVE-2002-1412.
Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.