Show filters
125 Total Results
Displaying 81-90 of 125
Sort by:
Attacker Value
Unknown

CVE-2007-5309

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
0
Attacker Value
Unknown

CVE-2007-4127

Disclosure Date: August 01, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if register_globals is enabled, thereby blocking exploitation. NOTE: CVE-2006-3210.a covers this issue in versions before 1.0
0
Attacker Value
Unknown

CVE-2007-3461

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
0
Attacker Value
Unknown

CVE-2007-3065

Disclosure Date: June 06, 2007 (last updated October 04, 2023)
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862.
0
Attacker Value
Unknown

CVE-2007-2962

Disclosure Date: May 31, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter.
0
Attacker Value
Unknown

CVE-2007-2458

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
0
Attacker Value
Unknown

CVE-2007-2457

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
0
Attacker Value
Unknown

CVE-2007-2076

Disclosure Date: April 18, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this problem existed only briefly in v1.0."
0
Attacker Value
Unknown

CVE-2007-1806

Disclosure Date: April 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the idcat parameter.
0
Attacker Value
Unknown

CVE-2006-7103

Disclosure Date: March 03, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
0