planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/432576/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/17753 | vdb entry exploit |
http://securityreason.com/securityalert/825 | third party advisory |
http://www.planetc.de/download/planetgallery/planetgallery.html |