Show filters
44 Total Results
Displaying 11-20 of 44
Sort by:
Attacker Value
Unknown

CVE-2008-6379

Disclosure Date: March 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown

CVE-2008-6084

Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.
0
Attacker Value
Unknown

CVE-2008-2449

Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to image.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-2207

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.
0
Attacker Value
Unknown

CVE-2008-1987

Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0
Attacker Value
Unknown

CVE-2008-1988

Disclosure Date: April 27, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows remote authenticated administrators to upload and execute arbitrary PHP files by uploading a file with an executable extension, then accessing it via a direct request to the file in the rwx_gallery directory. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1064

Disclosure Date: February 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in images.php in the Red Mexico RMSOFT Gallery System (GS) 2.0 module (aka rmgs) for XOOPS allows remote attackers to inject arbitrary web script or HTML via the q parameter.
0
Attacker Value
Unknown

CVE-2008-0611

Disclosure Date: February 06, 2008 (last updated October 04, 2023)
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-2643

Disclosure Date: May 13, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.
0
Attacker Value
Unknown

CVE-2007-1469

Disclosure Date: March 16, 2007 (last updated October 04, 2023)
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
0