Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2010-4693

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.
0
Attacker Value
Unknown

CVE-2009-1911

Disclosure Date: June 04, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
0
Attacker Value
Unknown

CVE-2008-5296

Disclosure Date: December 01, 2008 (last updated October 04, 2023)
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-4645

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
0
Attacker Value
Unknown

CVE-2006-3476

Disclosure Date: July 10, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown

CVE-2006-1696

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2006-0587

Disclosure Date: February 08, 2006 (last updated February 22, 2025)
Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file.
0
Attacker Value
Unknown

CVE-2006-0330

Disclosure Date: January 21, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).
0
Attacker Value
Unknown

CVE-2005-4228

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
0