Show filters
125 Total Results
Displaying 91-100 of 125
Sort by:
Attacker Value
Unknown

CVE-2007-0122

Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
0
Attacker Value
Unknown

CVE-2006-6354

Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976.
0
Attacker Value
Unknown

CVE-2006-5206

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.
0
Attacker Value
Unknown

CVE-2006-5205

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used.
0
Attacker Value
Unknown

CVE-2006-4321

Disclosure Date: August 24, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2006-3688

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2006-3563

Disclosure Date: July 13, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
0
Attacker Value
Unknown

CVE-2006-3476

Disclosure Date: July 10, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown

CVE-2006-3032

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
0
Attacker Value
Unknown

CVE-2006-2862

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter.
0