Lucene search

K
cve[email protected]CVE-2007-4127
HistoryAug 01, 2007 - 4:17 p.m.

CVE-2007-4127

2007-08-0116:17:00
web.nvd.nist.gov
21
cve-2007-4127
php
remote file inclusion
ralf image gallery
rig
raphael moll
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.268 Low

EPSS

Percentile

96.8%

PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if register_globals is enabled, thereby blocking exploitation. NOTE: CVE-2006-3210.a covers this issue in versions before 1.0

Affected configurations

NVD
Node
le_ralfralf_image_galleryMatch1.0

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.268 Low

EPSS

Percentile

96.8%

Related for CVE-2007-4127