Back
CVE-2004-2124
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| gallery_project | gallery | 1.3.1 |
| gallery_project | gallery | 1.3.2 |
| gallery_project | gallery | 1.3.3 |
| gallery_project | gallery | 1.4 |
| gallery_project | gallery | 1.4.1 |
GitHub Security Advisory GHSA-f4p5-2pxq-w62g
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers...
References (14)
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=index Patch
- http://marc.info/?l=bugtraq&m=107524414317693&w=2
- http://secunia.com/advisories/10712/
- http://www.gentoo.org/security/en/glsa/glsa-200402-04.xml
- http://www.osvdb.org/3737
- http://www.securityfocus.com/bid/9490
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14950
- http://gallery.menalto.com/modules.php?op=modload&name=News&file=index Patch
- http://marc.info/?l=bugtraq&m=107524414317693&w=2
- http://secunia.com/advisories/10712/
- http://www.gentoo.org/security/en/glsa/glsa-200402-04.xml
- http://www.osvdb.org/3737
- http://www.securityfocus.com/bid/9490
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14950
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
7.35%
Top 6% most likely to be exploited
Threat Score
22.2 / 100
Data Sources
NVD
EPSS
GitHub