VYPR
High severity7.2NVD Advisory· Published Jan 9, 2020· Updated Jun 16, 2026

CVE-2012-2931

CVE-2012-2931

Description

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.

Affected products

3
  • cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tinywebgallery:tinywebgallery:*:*:*:*:*:*:*:*range: <1.8.8
    • (no CPE)range: <1.8.8
  • TinyWebGallery/TinyWebGallerydescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.