thibaud-rohmer/PhotoShow

thibaud-rohmer/PhotoShow

Releases3
Frequency1 year 2 months
Last Release
Stars513
A free web gallery in PHP with drag-n-drop support

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.