Junglewise Threat Intelligence

CVE-2017-20250: Apptha Mac Photo Gallery path traversal in macdownload.php

CVE-2017-20250 · Severity: high · CVSS 7.5 · Published 2026-06-09

Executive brief

Mac Photo Gallery, a WordPress plugin used for managing image galleries, contains a security flaw that allows unauthorized individuals to download files from the web server. An attacker can exploit this to steal sensitive configuration files, potentially leading to the exposure of database credentials or other private site information. This could result in a full site compromise or data breach.

Technical details

A path traversal vulnerability (CWE-22) exists in Mac Photo Gallery 3.0 within the 'macdownload.php' component. The issue stems from insufficient sanitization of the 'albid' parameter, which allows an unauthenticated remote attacker to use directory traversal sequences (e.g., ../) to escape the intended directory. By sending a specially crafted HTTP request, an attacker can read and download sensitive files from the server, such as 'wp-load.php' or other system configuration files. An exploit for this vulnerability has been publicly documented in Exploit-DB.

Affected products

  • Apptha Mac Photo Gallery 3.0

Timeline

  • 2017-03-09: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-09: advisory: NVD/VulnCheck advisory published

References