Gallery Remote Code Execution...

- AV AC AU C I A
发布: 2002-12-28
修订: 2025-04-13

A new feature supporting the Windows XP publishing subsystem in Gallery 1.3.2 has introduced a security vulnerability nearly identical to that described in BID 5375. The PHP script 'publish_xp_docs.php' attempts to include a file, 'init.php', from a path constructed using an uninitiated PHP variable. Malicious remote clients may pass a value for that variable, specifying a remote server as the location of the include file

0%
暂无可用Exp或PoC
当前有0条受影响产品信息