Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote malicious users to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
tftgallery tftgallery 0.13 |