5.1

CVE-2006-3210

Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php.  NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Le RalfRalf Image Gallery Version0.6.5
Le RalfRalf Image Gallery Version0.7
Le RalfRalf Image Gallery Version0.7.1
Le RalfRalf Image Gallery Version0.7.2
Le RalfRalf Image Gallery Version0.7.3
Le RalfRalf Image Gallery Version0.7.4
Le RalfRalf Image Gallery Version0.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.3% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://rig.powerpulsar.com/#news
http://secunia.com/advisories/20771
Patch
Vendor Advisory
http://securityreason.com/securityalert/1136
http://www.majorsecurity.de/advisory/major_rls18.txt
http://www.osvdb.org/26753
http://www.osvdb.org/26754
http://www.osvdb.org/26755
http://www.osvdb.org/26756
http://www.securityfocus.com/archive/1/437818/100/0/threaded
http://www.securityfocus.com/archive/1/438645/100/100/threaded
http://www.securityfocus.com/bid/18548
http://www.vupen.com/english/advisories/2006/2477
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27256
https://exchange.xforce.ibmcloud.com/vulnerabilities/27257
https://exchange.xforce.ibmcloud.com/vulnerabilities/27259