Show filters
127 Total Results
Displaying 101-110 of 127
Sort by:
Attacker Value
Unknown

CVE-2006-3032

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
0
Attacker Value
Unknown

CVE-2006-2862

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter.
0
Attacker Value
Unknown

CVE-2006-2514

Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
0
Attacker Value
Unknown

CVE-2006-2079

Disclosure Date: April 27, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
0
Attacker Value
Unknown

CVE-2006-2080

Disclosure Date: April 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in portfolio_photo_popup.php in Verosky Media Instant Photo Gallery 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, which is not cleansed before calling the count_click function in includes/functions/fns_std.php. NOTE: this issue could produce resultant XSS.
0
Attacker Value
Unknown

CVE-2006-2052

Disclosure Date: April 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.
0
Attacker Value
Unknown

CVE-2006-2041

Disclosure Date: April 26, 2006 (last updated October 04, 2023)
PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2005-4228

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.
0
Attacker Value
Unknown

CVE-2005-4251

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.
0
Attacker Value
Unknown

CVE-2005-4250

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.
0