Snipe Gallery 存在多个PHP远程文件包含漏洞。远程攻击者可以借助多个脚本的cfg_admin_path参数的URL执行任意的PHP代码。这些脚本包含:(1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8) admin/gallery/gallery.php, (9) admin/gallery/image.php, 和 (10) admin/gallery/crop.php。
Snipe Gallery 存在多个PHP远程文件包含漏洞。远程攻击者可以借助多个脚本的cfg_admin_path参数的URL执行任意的PHP代码。这些脚本包含:(1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8) admin/gallery/gallery.php, (9) admin/gallery/image.php, 和 (10) admin/gallery/crop.php。