Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Wihphoto | Wihphoto | 0.86 (including) | 0.86 (including) |