5.1

CVE-2006-3210

Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php.  NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Le RalfRalf Image Gallery Version0.6.5
Le RalfRalf Image Gallery Version0.7
Le RalfRalf Image Gallery Version0.7.1
Le RalfRalf Image Gallery Version0.7.2
Le RalfRalf Image Gallery Version0.7.3
Le RalfRalf Image Gallery Version0.7.4
Le RalfRalf Image Gallery Version0.7.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.07% 0.893
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.