Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-27040
Disclosure Date: March 16, 2023 (last updated February 24, 2025)
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
0
Attacker Value
Unknown
CVE-2015-1000007
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Remote file download vulnerability in wptf-image-gallery v1.03
0
Attacker Value
Unknown
CVE-2014-7153
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2009-3366
Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
0
Attacker Value
Unknown
CVE-2009-3367
Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-1446
Disclosure Date: April 27, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-6488
Disclosure Date: March 18, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.
0
Attacker Value
Unknown
CVE-2008-5037
Disclosure Date: November 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0
Attacker Value
Unknown
CVE-2008-2675
Disclosure Date: June 12, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-5310
Disclosure Date: October 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0