High
CVSS 7.5
Overview
publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code.
publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrar...
publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code.
This vulnerability is rated 🟠 HIGH.
Recommended actions: