CVE-2012-2931

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
09/01/2020
Last modified:
21/11/2024

Description

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:* 1.8.8 (excluding)