Description
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51443
www.exploit-db.com/exploits/51443 (ExploitDB-51443)
www.tinywebgallery.com/ (Official Product Webpage)
www.vulncheck.com/...-execution-via-unrestricted-file-upload (VulnCheck Advisory: TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.