Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-27040

Disclosure Date: March 16, 2023 (last updated February 24, 2025)
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
Attacker Value
Unknown

CVE-2015-1000007

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Remote file download vulnerability in wptf-image-gallery v1.03
0
Attacker Value
Unknown

CVE-2014-7153

Disclosure Date: September 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2009-3366

Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
0
Attacker Value
Unknown

CVE-2009-3367

Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2009-1446

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6488

Disclosure Date: March 18, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.
0
Attacker Value
Unknown

CVE-2008-5037

Disclosure Date: November 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown

CVE-2008-2675

Disclosure Date: June 12, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-5310

Disclosure Date: October 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0