Flash Image Gallery suffers from a direct download vulnerability where config.xml, the file containing the username and password for the administrator, can be directly accessed by anyone remotely. Advisory is in Spanish.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/61793/fig-xml.txt
Source: https://packetstormsecurity.com/files/61793/fig-xml.txt.html