CVE-2007-0682
JV2 Folder Gallery < 3.0.2 - Remote File Inclusion via galleryfilesdir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0682. PoCs published by ThE dE@Th.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in JV2 Folder Gallery 3.0.2 by manipulating the 'galleryfilesdir' parameter in template.php to include a remote shell. The vulnerability allows for remote code execution (RCE) due to improper input validation.
Description
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in JV2 Folder Gallery 3.0.2 by manipulating the 'galleryfilesdir' parameter in template.php to include a remote shell. The vulnerability allows for remote code execution (RCE) due to improper input validation.