Month Of Abysssec Undisclosed Bugs – InterPhoto Gallery versions 2.4.0 and below suffer from shell upload, cross site request forgery, cross site scripting and disclosure vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/93563/moaub06-interphoto.pdf
Source: https://packetstormsecurity.com/files/93563/Month-Of-Abysssec-Undisclosed-Bugs-InterPhoto-Gallery-2.4.0.html

