PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
Loading...
Loading...
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.
September 12, 2006
April 16, 2026
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-4720
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.