vendor:
Folder Gallery
by:
PeTrO
9.8
CVSS
CRITICAL
Remote Code Execution
79
CWE
Product Name: Folder Gallery
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
JV2 Folder Gallery Remote Admin Credentials Exploit
This exploit allows an attacker to retrieve the admin credentials from the JV2 Folder Gallery script. By sending a specially crafted GET request to the 'download.php' file, the attacker can download the 'gallerysetup.php' file which contains the admin credentials.
Mitigation:
1. Update the JV2 Folder Gallery script to the latest version. 2. Implement strong password policies for admin accounts. 3. Regularly monitor and log server access.