Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3600 (Gallery)

BugsAlert Home > CVE-2008-3600 (Gallery)
 
 

Directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1.5.7 and 1.6-alpha3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter within a modload action.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3600

Learn more about CVE-2008-3600 (Gallery)
 
Tags: cve-2008-3600 gallery

Related Items

      Zeeways Shaadi Clone Authentication Bypass Vulnerability

      ICQ Personal Status Processing Buffer Overflow

      DB2 Multiple Vulnerabilities

      Fedora 9 Update: ktorrent-3.1.4-1.fc9

      MS08-021 ? Critical: Vulnerability in GDI Could Allow Remote Code Execution (948590) - Version:1.2

      TROJ_AGENT.ASAK

      CVE-2008-3900 (bios)

 

Pixel