Your host admin is blowing smoke. There is no CGI in a jAlbum-produced gallery - it's not database driven. In fact, there's no server-side processing in such a gallery at all - it consists solely of HTML, CSS, and Javascript, all of which are simply passed to the visitor's PC, where the only "processing" takes place. Nothing is passed back to the server.
A jAlbum gallery is not directly hackable. It can be affected only if a hacker gains access to your host by some other means, like hacking your PC or your cPanel account. The album itself has no pathway for a hacker to exploit.
|