CVE-2008-1730

ARWScripts Gallery Script Lite - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1730. PoCs published by JIKO.

AI-analyzed exploit summary This is a writeup describing a Local File Inclusion (LFI) vulnerability in gallery-script-lite. The exploit demonstrates how to include local files via the 'path' parameter in download.html, potentially leading to information disclosure.

Description

Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as of 20080411, allows remote attackers to read arbitrary local files via directory traversal sequences in the path parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by JIKO · textwebappsphp
https://www.exploit-db.com/exploits/5419

This is a writeup describing a Local File Inclusion (LFI) vulnerability in gallery-script-lite. The exploit demonstrates how to include local files via the 'path' parameter in download.html, potentially leading to information disclosure.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: gallery-script-lite
No auth needed
Prerequisites: access to the vulnerable download.html endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/44253
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5419
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29746
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41742
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28718

Scores

EPSS 0.0292
EPSS Percentile 85.2%

Details

CWE
CWE-22
Status published
Products (1)
arwscripts/gallery_script_lite
Published Apr 11, 2008
Tracked Since Feb 18, 2026