Show filters
67 Total Results
Displaying 31-40 of 67
Sort by:
Attacker Value
Unknown

CVE-2008-1296

Disclosure Date: March 12, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote attackers to inject arbitrary web script or HTML via the file parameter to (1) watermark.php and (2) catalog_watermark.php in core/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-0752

Disclosure Date: February 13, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.
0
Attacker Value
Unknown

CVE-2008-0504

Disclosure Date: January 31, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
0
Attacker Value
Unknown

CVE-2007-5292

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory parameter.
0
Attacker Value
Unknown

CVE-2007-4916

Disclosure Date: September 17, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
0
Attacker Value
Unknown

CVE-2007-2458

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
0
Attacker Value
Unknown

CVE-2007-2457

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
0
Attacker Value
Unknown

CVE-2007-1600

Disclosure Date: March 22, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.
0
Attacker Value
Unknown

CVE-2006-7103

Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
0
Attacker Value
Unknown

CVE-2007-0815

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the s parameter. NOTE: the thumbnails.asp vector is already covered by CVE-2006-3023.
0