Sploitus

CVE-2004-1466

1 known exploit for CVE-2004-1466

The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root.

Affected products
Gallery
Gallery Project Gallery
= 1.4.4
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
5.2% (92th percentile)
NVD status
Modified
Published
2005-02-13
CVE-2004-1466 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2004-1466

Proof-of-concept code and exploit modules indexed by Sploitus