CVE-2006-1668

Eric Gerdes Crafty Syntax Image Gallery <3.1g - Authenticated RCE

Title source: llm
STIX 2.1

Description

newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by undefined1_ · perlwebappsphp
https://www.exploit-db.com/exploits/1645

Scores

EPSS 0.0745
EPSS Percentile 91.8%

Details

Status published
Products (1)
crafty_syntax_image_gallery/crafty_syntax_image_gallery < 3.1g
Published Apr 07, 2006
Tracked Since Feb 18, 2026