Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.50%
Published
Mar 16, 2007
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
Weaknesses (CWE)
Affected Products (1)
References (8)