Multiple vulnerabilities have been identified in DBImageGallery, which could be exploited by attackers to execute arbitrary commands. These issues are due to input validation errors in the "admin/attributes.php", "admin/images.php", "admin/scan.php", "includes/attributes.php", "includes/db_utils.php", "includes/images.php", "includes/utils.php" and "includes/values.php" scripts when processing the "donsimg_base_path" parameter, which could be exploited by remote attackers to include malicious scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: DBImageGallery version 1.2.2 and prior