CVE-2006-1668
Eric Gerdes Crafty Syntax Image Gallery <3.1g - Authenticated RCE
Title source: llmDescription
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by undefined1_ · perlwebappsphp
https://www.exploit-db.com/exploits/1645
References (8)
Scores
EPSS
0.0745
EPSS Percentile
91.8%
Details
Status
published
Products (1)
crafty_syntax_image_gallery/crafty_syntax_image_gallery
< 3.1g
Published
Apr 07, 2006
Tracked Since
Feb 18, 2026