Show filters
127 Total Results
Displaying 111-120 of 127
Sort by:
Attacker Value
Unknown

CVE-2005-2676

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data.
0
Attacker Value
Unknown

CVE-2005-2331

Disclosure Date: July 20, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter.
0
Attacker Value
Unknown

CVE-2005-1948

Disclosure Date: June 09, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.
0
Attacker Value
Unknown

CVE-2005-1172

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
0
Attacker Value
Unknown

CVE-2005-0375

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.
0
Attacker Value
Unknown

CVE-2005-0377

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.
0
Attacker Value
Unknown

CVE-2005-0376

Disclosure Date: January 12, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.
0
Attacker Value
Unknown

CVE-2004-1835

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.
0
Attacker Value
Unknown

CVE-2004-2223

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.
0
Attacker Value
Unknown

CVE-2004-1984

Disclosure Date: May 02, 2004 (last updated February 22, 2025)
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.
0