Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Expl0!Ts

#36414of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2012-5942
7.5
2012-10-09
Tinywebgallery · Tinywebgallery · CVE-2012-5347
**Name of the Vulnerable Software and Affected Versions** TinyWebGallery version 1.8.3 **Description** The issue allows remote attackers to execute arbitrary code via shell metacharacters in the `command` parameter to (1) inc/filefunctions.inc or (2) info.php. **Recommendations** For TinyWebGallery version 1.8.3, consider restricting access to the `command` parameter in the affected files until a patch is available. As a temporary workaround, avoid using the `command` parameter in the inc/filefunctions.inc and info.php files to minimize the risk of exploitation.