← Back

Kwalbum

kwalbum

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Kwalbum
kwalbum

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kwalbum
1Kwalbum
Apr 23, 2026
Dec 19, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a fi...Show more
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information.Show less