admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types. Successful exploitation requires administrative user privileges.
This vulnerability is addressed in the following product release:
PlaNet Concept, planetGallery, 14.07.2006
Publication date: Mon, 24 Jul 2006 17:19:00 +0000