CVE-2008-4484 Information

Description

main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to \users\ as demonstrated via index.php.

Reference

http://secunia.com/advisories/32058 http://securityreason.com/securityalert/4365 http://www.attrition.org/pipermail/vim/2008-October/002083.html http://www.securityfocus.com/archive/1/496763/100/0/threaded http://www.securityfocus.com/bid/31430 https://exchange.xforce.ibmcloud.com/vulnerabilities/45443 https://www.exploit-db.com/exploits/6586

Share on: