peter bassill · operator
$ cve CVE-2010-2336 JSON

CVE-2010-2336 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.4% (pctl 83)

Patch early

A public exploit exists.

Description

index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.35% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2010-06-18
Last modified2026-06-16

Affected (1)

VendorProduct
yamamahyamamah

Public exploits

SourceTitleDate
exploit-dbYamamah - 'news' SQL Injection / Source Code Disclosure2010-06-12

References

→ the Explorer  ·  watch your stack  ·  NVD