CVE-2006-4166
TinyWebGallery <1.5 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Mehmet Ince · textwebappsphp
https://www.exploit-db.com/exploits/2158
References (7)
Scores
EPSS
0.1119
EPSS Percentile
93.4%
Classification
Status
draft
Affected Products (3)
tinywebgallery/tinywebgallery
< 1.5
tinywebgallery/tinywebgallery
tinywebgallery/tinywebgallery
Timeline
Published
Aug 16, 2006
Tracked Since
Feb 18, 2026