upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-10-24T23:00:00

Updated: 2024-08-08T02:28:03.652Z

Reserved: 2007-10-24T00:00:00

Link: CVE-2003-1489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2003-12-31T05:00:00.000

Modified: 2016-10-18T02:39:45.560

Link: CVE-2003-1489

cve-icon Redhat

No data.