CVE Database
/

CVE-2006-3210

Back to search

CVE-2006-3210

Published: Jun 24, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.

VendorProductVersions

n/a

n/a

affected
n/a

References

18548
vdb-entry
x_refsource_BID
26753
vdb-entry
x_refsource_OSVDB
1136
third-party-advisory
x_refsource_SREASON
26756
vdb-entry
x_refsource_OSVDB
26754
vdb-entry
x_refsource_OSVDB
26755
vdb-entry
x_refsource_OSVDB
ADV-2006-2477
vdb-entry
x_refsource_VUPEN
20771
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now