CVE-2006-1412

TFT Gallery 0.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.

Exploits (1)

exploitdb WORKING POC VERIFIED
by undefined1_ · perlwebappsphp
https://www.exploit-db.com/exploits/1611

Scores

EPSS 0.1288
EPSS Percentile 94.1%

Details

Status published
Products (1)
tft_gallery/tft_gallery 0.10
Published Mar 28, 2006
Tracked Since Feb 18, 2026