JV2 Folder Gallery 3.1.1 (popup_slideshow.php) Multiple Vulnerability
JV2 Folder Gallery 3.1.1 is vulnerable to Local File Inclusion (LFI) and Remote Code Execution (RCE). An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. The vulnerable code is located in the popup_slideshow.php file, which includes the language, gallerytheme, and file_handling.php files without proper validation. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable application. The attacker can use the LFI vulnerability to include a malicious file from the local system or a remote system. The attacker can also use the RCE vulnerability to execute arbitrary code on the vulnerable system.