Show filters
44 Total Results
Displaying 31-40 of 44
Sort by:
Attacker Value
Unknown

CVE-2006-1219

Disclosure Date: March 14, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.
0
Attacker Value
Unknown

CVE-2006-1127

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.
0
Attacker Value
Unknown

CVE-2006-1128

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.
0
Attacker Value
Unknown

CVE-2006-1126

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTE_ADDR.
0
Attacker Value
Unknown

CVE-2006-0927

Disclosure Date: February 28, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.
0
Attacker Value
Unknown

CVE-2005-4295

Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2005-4023

Disclosure Date: December 05, 2005 (last updated February 22, 2025)
Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors.
0
Attacker Value
Unknown

CVE-2005-4021

Disclosure Date: December 05, 2005 (last updated February 22, 2025)
The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2005-3477

Disclosure Date: November 03, 2005 (last updated February 22, 2025)
Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery.
0
Attacker Value
Unknown

CVE-2005-3395

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.
0