EZPhotoSales 1.9.3 and earlier has a default admin account for galleries, which allows remote attackers to access arbitrary galleries by specifying this username.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ez_photo_sales | Ez_photo_sales | * | 1.9.3 (including) |