PHPmyGallery Local File Disclosure and Cross Site Scripting Vulnerabilities

Summary
PHPmyGallery is prone to multiple cross-site scripting vulnerabilities and a local file-disclosure vulnerability because it fails to sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks PHPmyGallery 1.51.010 and prior versions are vulnerable.
References