mAlbum "gal" Parameter Handling Remote Information Disclosure Vulnerability
Description
A vulnerability has been identified in mAlbum, which could be exploited by attackers to gain knowledge of sensitive information. This flaw is due to an input validation error in the "cached_album()" [functions.php] function (called in "malbum.php") that does not validate the "gal" parameter, which could be exploited by attackers to disclose file names of arbitrary images.