HTTP: PHP Gallery HTTP_VARS In URL

This signature detects attempts to exploit a known vulnerability against Gallery, a Web-based photo management application. Gallery uses the variables HTTP_POST_VARS, HTTP_GET_VARS, HTTP_COOKIE_VARS, and HTTP_POST_FILES to transfer data between pages, including the GALLERY_BASEDIR variable. Attackers can manually control these variables to include a malicious setting for GALLERY_BASEDIR; enabling them to execute arbitrary PHP code on the Gallery server with the permissions of the HTTP server.

Extended Description

Gallery is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. This issue is present in several PHP script files provided with Gallery. An attacker may exploit this by supplying a path to a file on a remote host as a value for the 'GALLERY_BASEDIR' parameter.

Affected Products

Bharat_mediratta gallery

Short Name
HTTP:PHP:GALLERY:HTTP-VARS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2002-1412 Gallery HTTP_VARS In PHP URL bid:5375
Release Date
02/05/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Bharat_mediratta

CVSS Score

7.5

Found a potential security threat?