Title: Thyme 'export.php' Local File Include Vulnerability
Severity: HIGH
Description:
Thyme is a PHP-based photo calendar application.
The application is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input to the 'export_to' parameter of the 'export.php' script.
An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
Thyme 1.3 is vulnerable; other versions may also be affected
Affected Products:
- EXtrovert Software Thyme 1.3
References:
- EXtrovert Software: Thyme Homepage
