
thibaud-rohmer/PhotoShow
Releases3
Frequency1 year 2 months
Last Release
Stars513
A free web gallery in PHP with drag-n-drop support
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 7.2 HIGH | — | ||
PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process. | |||