download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
References
Configurations
Information
Published : 2007-03-16 14:19
Updated : 2017-10-10 18:31
NVD link : CVE-2007-1478
Mitre link : CVE-2007-1478
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
mcgallery
- mcgallery