CVE-2004-1466
Gallery <1.4.4_p2 - RCE
Title source: llmDescription
The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by aCiDBiTS · phpwebappsphp
https://www.exploit-db.com/exploits/24383
References (5)
Scores
EPSS
0.1407
EPSS Percentile
94.4%
Details
Status
published
Products (1)
gallery_project/gallery
1.4.4
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026