Sanybee · Sanybee Gallery · CVE-2007-6648
**Name of the Vulnerable Software and Affected Versions**
SanyBee Gallery versions 0.1.0 through 0.1.1
**Description**
The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the `p` parameter. This can be achieved by manipulating the `p` parameter in the index.php file.
**Recommendations**
For SanyBee Gallery versions 0.1.0 through 0.1.1, consider restricting access to the index.php file until a patch is available. As a temporary workaround, avoid using the `p` parameter in the index.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.