CVE-2010-2336 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.35% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-06-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| yamamah | yamamah |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Yamamah - 'news' SQL Injection / Source Code Disclosure | 2010-06-12 |
References
→ the Explorer · watch your stack · NVD