EZPhotoSales 1.9.3 and earlier allows remote attackers to download arbitrary image files via (1) a direct request for a URL under OnlineViewing/galleries/ or (2) navigation of the gallery user interface with JavaScript disabled.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ez_photo_sales | Ez_photo_sales | 1.9.3 (including) | 1.9.3 (including) |