CVE-2001-1234

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/10/2001
Last modified:
03/04/2025

Description

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gallery_project:gallery:1.1:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.2:*:*:*:*:*:*:*
cpe:2.3:a:gallery_project:gallery:1.2.1:*:*:*:*:*:*:*