CVE-2006-4166 – TinyWebGallery Remote PHP Code Execution RCE

Description

PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.


Vulnerability Information

  • Product / Framework: Tinywebgallery
  • Vendor Domain: wordpress.org
  • Vulnerability Type: File Includion
  • CVE Details: View Full CVE Details →