Lucene search

K
cveMitreCVE-2004-1408
HistoryFeb 12, 2005 - 5:00 a.m.

CVE-2004-1408

2005-02-1205:00:00
mitre
web.nvd.nist.gov
20
cve-2004-1408
image gallery
web application
remote attack
file upload vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

High

EPSS

0.009

Percentile

83.0%

The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files.

Affected configurations

Nvd
Node
singaporeimage_gallery_web_applicationMatch0.9.10
VendorProductVersionCPE
singaporeimage_gallery_web_application0.9.10cpe:2.3:a:singapore:image_gallery_web_application:0.9.10:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

High

EPSS

0.009

Percentile

83.0%

Related for CVE-2004-1408