CVE-2017-20250

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.
Configurations

No configuration.

History

21 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Mac Photo Gallery 3.0 contiene una vulnerabilidad de salto de ruta que permite a atacantes no autenticados descargar archivos arbitrarios manipulando el parĂ¡metro albid. Los atacantes pueden enviar solicitudes a macdownload.php con secuencias de salto de directorio para acceder a archivos sensibles como wp-load.php fuera del directorio del plugin previsto.

09 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 13:16

Updated : 2026-07-21 07:10


NVD link : CVE-2017-20250

Mitre link : CVE-2017-20250

CVE.ORG link : CVE-2017-20250


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')