CVE-2017-20250

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-09 13:16

Updated : 2026-07-21 07:10


NVD link : CVE-2017-20250

Mitre link : CVE-2017-20250

CVE.ORG link : CVE-2017-20250


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')