Back to search
CVE-2012-10052
Published: Aug 8, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files directly into the web-accessible egallery/ directory. This results in full remote code execution under the web server context.
| Vendor | Product | Versions |
|---|---|---|
EGallery | EGallery | affected 1.2 |
Weaknesses (CWE)
References
https://www.vulncheck.com/advisories/egallery-arbitrary-php-file-upload
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now