PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/10943 | vdb entry |
http://www.securityfocus.com/archive/1/304611 | patch vendor advisory mailing list |
http://www.securityfocus.com/bid/6489 | patch vdb entry |