CVE-2006-4166
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.
- Affected products
- Tinywebgallery
- Tinywebgallery
- ≤ 1.5, 1.3, 1.4
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 3.6% (88th percentile)
- NVD status
- Modified
- Published
- 2006-08-16
CVE-2006-4166 at NVD
1 known exploit for CVE-2006-4166
Proof-of-concept code and exploit modules indexed by Sploitus