Show filters
125 Total Results
Displaying 61-70 of 125
Sort by:
Attacker Value
Unknown
CVE-2008-6084
Disclosure Date: February 06, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.
0
Attacker Value
Unknown
CVE-2008-5037
Disclosure Date: November 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown
CVE-2008-4645
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
0
Attacker Value
Unknown
CVE-2008-4627
Disclosure Date: October 21, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php.
0
Attacker Value
Unknown
CVE-2008-4531
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to queries. NOTE: this might be the same issue as CVE-2008-4338.
0
Attacker Value
Unknown
CVE-2008-4530
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote authenticated users with permissions to inject arbitrary web script or HTML via unspecified vectors related to posting of answers.
0
Attacker Value
Unknown
CVE-2008-4509
Disclosure Date: October 09, 2008 (last updated October 04, 2023)
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory.
0
Attacker Value
Unknown
CVE-2008-4484
Disclosure Date: October 08, 2008 (last updated October 04, 2023)
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.
0
Attacker Value
Unknown
CVE-2008-4483
Disclosure Date: October 08, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.
0
Attacker Value
Unknown
CVE-2008-3486
Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
0