Show filters
179 Total Results
Displaying 101-110 of 179
Sort by:
Attacker Value
Unknown
CVE-2015-3922
Disclosure Date: May 27, 2015 (last updated October 05, 2023)
Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.
0
Attacker Value
Unknown
CVE-2015-3921
Disclosure Date: May 27, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.
0
Attacker Value
Unknown
CVE-2015-1393
Disclosure Date: February 02, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2015-1055
Disclosure Date: January 16, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-9441
Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2) ll__opt[image2_url] or (3) ll__opt[image3_url] parameter in a ll_save_settings action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-6315
Disclosure Date: October 10, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-4529
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
0
Attacker Value
Unknown
CVE-2012-1614
Disclosure Date: September 04, 2012 (last updated October 05, 2023)
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2012-1613
Disclosure Date: September 04, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter.
0
Attacker Value
Unknown
CVE-2010-4948
Disclosure Date: October 09, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
0