TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters “twg_browserx” and “twg_browsery” in the page image.php.
CPE | Name | Operator | Version |
---|---|---|---|
tinywebgallery | le | 1.8.9 |