TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
2020-02-03T15:15:11.273
2024-11-21T01:52:04.800
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Application | tinywebgallery | tinywebgallery | ≤ 1.8.9 | Yes |