TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Tinywebgallery |
Tinywebgallery |
1.8.3 (including) |
1.8.3 (including) |
References