Gravy Media Photo Host "file" Parameter File Disclosure Vulnerability
Description
A vulnerability has been identified in Gravy Media Photo Host, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "forcedownload.php" script that does not validate the "file" parameter, which could be exploited to disclose the contents of arbitrary files.
Vulnerable Products
Vulnerable Software: Gravy Media Photo Host version 1.0.8 and prior