PT-2026-47773 · Undefined · Undefined

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2017-20250

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2017-20250

Affected Products

Undefined