CVE-2007-0329
JV2 Folder Gallery - Unauthenticated Arbitrary File Read via download.php file Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0329. PoCs published by PeTrO.
AI-analyzed exploit summary This exploit targets a path traversal vulnerability in JV2 Folder Gallery to retrieve sensitive configuration data. It sends a crafted HTTP GET request to download the 'gallerysetup.php' file, which contains admin credentials.
Description
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php. NOTE: this issue might be resultant from a directory traversal vulnerability.
Exploits (1)
This exploit targets a path traversal vulnerability in JV2 Folder Gallery to retrieve sensitive configuration data. It sends a crafted HTTP GET request to download the 'gallerysetup.php' file, which contains admin credentials.