Unrated severityNVD Advisory· Published Aug 16, 2006· Updated Apr 16, 2026
CVE-2006-4166
CVE-2006-4166
Description
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.
Affected products
3cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:*range: <=1.5
- cpe:2.3:a:tinywebgallery:tinywebgallery:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:tinywebgallery:tinywebgallery:1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- securitytracker.com/idnvdExploit
- securityreason.com/securityalert/1393nvd
- www.securityfocus.com/archive/1/442818/100/0/threadednvd
- www.securityfocus.com/archive/1/443353/100/0/threadednvd
- www.securityfocus.com/archive/1/445089/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28317nvd
- www.exploit-db.com/exploits/2158nvd
News mentions
0No linked articles in our index yet.