VULNERABILITY INTELLIGENCE
CVE-2004-2124
CVSS score5 MEDIUM
EPSS probability7.35%
CISA KEVNot currently listed
Published2004-12-31
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Description
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.