Gallery 1.4 has a file include vulnerability where a remote PHP file can be included that will get executed on the local server.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31812/gallery14.txt
Source: https://packetstormsecurity.com/files/31812/gallery14.txt.html

