Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wabbit_php_gallery | Wabbit | 0.9 (including) | 0.9 (including) |