Show filters
179 Total Results
Displaying 121-130 of 179
Sort by:
Attacker Value
Unknown

CVE-2008-6789

Disclosure Date: May 04, 2009 (last updated October 04, 2023)
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.
0
Attacker Value
Unknown

CVE-2008-6348

Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0531

Disclosure Date: February 11, 2009 (last updated October 04, 2023)
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
0
Attacker Value
Unknown

CVE-2008-5641

Disclosure Date: December 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
0
Attacker Value
Unknown

CVE-2008-3486

Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
0
Attacker Value
Unknown

CVE-2008-3481

Disclosure Date: August 05, 2008 (last updated October 04, 2023)
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2008-1875

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter.
0
Attacker Value
Unknown

CVE-2008-1841

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.
0
Attacker Value
Unknown

CVE-2008-1840

Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
0
Attacker Value
Unknown

CVE-2008-1711

Disclosure Date: April 09, 2008 (last updated October 04, 2023)
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
0