CVE-2006-0899

4images image_gallery_management_system < 1.7.1 - Directory Traversal via Template Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0899. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets a directory traversal and arbitrary local file inclusion vulnerability in 4Images <= 1.7.1. It uploads a malicious .jpg file with EXIF metadata containing PHP code, then executes it via the vulnerable 'template' parameter.

Description

Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1533

This exploit targets a directory traversal and arbitrary local file inclusion vulnerability in 4Images <= 1.7.1. It uploads a malicious .jpg file with EXIF metadata containing PHP code, then executes it via the vulnerable 'template' parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: 4Images <= 1.7.1
Auth required
Prerequisites: Valid user credentials for authentication · Write access to upload directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19026
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24938
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1533
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/518
Various Sources x_refsource_misc
http://retrogod.altervista.org/4images_171_adv.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/426468/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23529
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0754
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16855

Scores

EPSS 0.0976
EPSS Percentile 94.9%

Details

Status published
Products (1)
4images/image_gallery_management_system < 1.7.1
Published Feb 27, 2006
Tracked Since Feb 18, 2026