Show filters
179 Total Results
Displaying 101-110 of 179
Sort by:
Attacker Value
Unknown

CVE-2015-3922

Disclosure Date: May 27, 2015 (last updated October 05, 2023)
Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.
0
Attacker Value
Unknown

CVE-2015-3921

Disclosure Date: May 27, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.
0
Attacker Value
Unknown

CVE-2015-1393

Disclosure Date: February 02, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2015-1055

Disclosure Date: January 16, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-9441

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2) ll__opt[image2_url] or (3) ll__opt[image3_url] parameter in a ll_save_settings action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-6315

Disclosure Date: October 10, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-4529

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
0
Attacker Value
Unknown

CVE-2012-1614

Disclosure Date: September 04, 2012 (last updated October 05, 2023)
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2012-1613

Disclosure Date: September 04, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter.
0
Attacker Value
Unknown

CVE-2010-4948

Disclosure Date: October 09, 2011 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
0