Show filters
43 Total Results
Displaying 21-30 of 43
Sort by:
Attacker Value
Unknown

CVE-2010-4353

Disclosure Date: January 25, 2011 (last updated October 04, 2023)
Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
0
Attacker Value
Unknown

CVE-2010-4693

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.
0
Attacker Value
Unknown

CVE-2010-1186

Disclosure Date: April 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
0
Attacker Value
Unknown

CVE-2009-4064

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles.
0
Attacker Value
Unknown

CVE-2009-2233

Disclosure Date: June 26, 2009 (last updated October 04, 2023)
The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1.
0
Attacker Value
Unknown

CVE-2009-1911

Disclosure Date: June 04, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.
0
Attacker Value
Unknown

CVE-2008-6317

Disclosure Date: February 27, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf[lang] parameter, a different issue than CVE-2008-6318. NOTE: this might be the same issue as CVE-2008-6316.
0
Attacker Value
Unknown

CVE-2008-6318

Disclosure Date: February 27, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter, a different vector than CVE-2008-6317.
0
Attacker Value
Unknown

CVE-2008-5598

Disclosure Date: December 16, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary directories via a .. (dot dot) in the group parameter.
0
Attacker Value
Unknown

CVE-2008-5296

Disclosure Date: December 01, 2008 (last updated October 04, 2023)
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.
0