Show filters
109 Total Results
Displaying 91-100 of 109
Sort by:
Attacker Value
Unknown
CVE-2007-3229
Disclosure Date: June 14, 2007 (last updated October 04, 2023)
index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2007-1469
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
0
Attacker Value
Unknown
CVE-2006-6932
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp.
0
Attacker Value
Unknown
CVE-2006-6195
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.
0
Attacker Value
Unknown
CVE-2006-6196
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter).
0
Attacker Value
Unknown
CVE-2006-3210
Disclosure Date: June 24, 2006 (last updated October 04, 2023)
Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2006-2214
Disclosure Date: May 05, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.
0
Attacker Value
Unknown
CVE-2006-1667
Disclosure Date: April 07, 2006 (last updated February 22, 2025)
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s from being set within slides.php.
0
Attacker Value
Unknown
CVE-2006-1659
Disclosure Date: April 07, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in images.php.
0
Attacker Value
Unknown
CVE-2006-1668
Disclosure Date: April 07, 2006 (last updated February 22, 2025)
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.
0