漏洞描述 Google Picasa是美国谷歌(Google)公司的一套免费的图片管理工具。该工具可协助用户在计算机上查找、修改和共享图片。 Google Picasa在处理JPEG图像的实现上存在远程代码执行漏洞,远程攻击者可利用此漏洞以当前用户权限执行任意代码,造成拒绝服务。
相关漏洞推荐 POC freshrss-api: FreshRSS Google Reader API Exposure POC gcloudignore-file-exposure: Google Cloud Ignore File Exposure POC google-calendar-exposure: Google Calendar - Exposure POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure POC CVE-2025-12139: Integrate Google Drive <= 1.5.3 - Information Disclosure POC gcs-bucket-listing: Google Cloud Storage - Public Bucket Listing POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure POC CVE-2025-11307: WP Google Maps < 9.0.48 - Cross-Site Scripting POC wp-easy-google-fonts-log-disclosure: WordPress Easy Google Fonts - Error Log Disclosure WordPress Google for WooCommerce /wp-content/plugins/google-listings-and-ads/vendor/googleads/google-ads-php/scripts/print_php_information.php 信息泄露漏洞(CVE-2024-10486) POC CVE-2010-1306: Joomla! Component Picasa 2.0 - Local File Inclusion POC CVE-2010-2507: Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion POC CVE-2015-2755: WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting