Show filters
200 Total Results
Displaying 141-150 of 200
Sort by:
Attacker Value
Unknown
CVE-2008-5042
Disclosure Date: November 12, 2008 (last updated October 04, 2023)
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.
0
Attacker Value
Unknown
CVE-2008-3486
Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
0
Attacker Value
Unknown
CVE-2008-3481
Disclosure Date: August 05, 2008 (last updated October 04, 2023)
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2008-1841
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.
0
Attacker Value
Unknown
CVE-2008-1840
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
0
Attacker Value
Unknown
CVE-2008-1551
Disclosure Date: March 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown
CVE-2008-0660
Disclosure Date: February 08, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.
0
Attacker Value
Unknown
CVE-2008-0506
Disclosure Date: January 31, 2008 (last updated October 04, 2023)
include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.
0
Attacker Value
Unknown
CVE-2008-0505
Disclosure Date: January 31, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.
0
Attacker Value
Unknown
CVE-2008-0504
Disclosure Date: January 31, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
0