Back

CVE-2004-2124

The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
gallery_project gallery 1.3.1
gallery_project gallery 1.3.2
gallery_project gallery 1.3.3
gallery_project gallery 1.4
gallery_project gallery 1.4.1

GitHub Security Advisory GHSA-f4p5-2pxq-w62g

The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 7.35%

Top 6% most likely to be exploited

Threat Score 22.2 / 100

Data Sources

NVD EPSS GitHub