The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18531
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1405