High severity7.2NVD Advisory· Published Jan 9, 2020· Updated Jun 16, 2026
CVE-2012-2931
CVE-2012-2931
Description
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
Affected products
3cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:*range: <1.8.8
- (no CPE)range: <1.8.8
- TinyWebGallery/TinyWebGallerydescription
Patches
Vulnerability mechanics
References
1- www.htbridge.com/advisory/HTB23093nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.