Description
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by undefined1_ · perlwebappsphp
https://www.exploit-db.com/exploits/1611
References (7)
Scores
EPSS
0.1288
EPSS Percentile
94.1%
Details
Status
published
Products (1)
tft_gallery/tft_gallery
0.10
Published
Mar 28, 2006
Tracked Since
Feb 18, 2026