Unrated severityNVD Advisory· Published Mar 2, 2007· Updated Apr 23, 2026
CVE-2007-1164
CVE-2007-1164
Description
Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.
Affected products
1- cpe:2.3:a:dbscripts:dbimagegallery:1.2.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- www.securityfocus.com/bid/22657nvdExploit
- osvdb.org/34937nvd
- osvdb.org/34938nvd
- osvdb.org/34939nvd
- osvdb.org/34940nvd
- osvdb.org/34941nvd
- osvdb.org/34942nvd
- osvdb.org/34943nvd
- osvdb.org/34944nvd
- www.securityfocus.com/archive/1/461741/100/0/threadednvd
- www.securityfocus.com/archive/1/462142/100/0/threadednvd
- www.vupen.com/english/advisories/2007/0692nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/32612nvd
- www.exploit-db.com/exploits/3353nvd
News mentions
0No linked articles in our index yet.