Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2008-0138

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.
0
Attacker Value
Unknown

CVE-2007-2458

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
0
Attacker Value
Unknown

CVE-2007-2457

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
0
Attacker Value
Unknown

CVE-2007-1107

Disclosure Date: February 26, 2007 (last updated October 04, 2023)
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.
0
Attacker Value
Unknown

CVE-2007-0122

Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
0
Attacker Value
Unknown

CVE-2006-2514

Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
0
Attacker Value
Unknown

CVE-2005-4228

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
0
Attacker Value
Unknown

CVE-2005-2676

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data.
0
Attacker Value
Unknown

CVE-2004-2124

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.
0
Attacker Value
Unknown

CVE-2003-1428

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.
0