malbum records
3 published records for vendor malbum.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2007-1045No exploit | mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gmalbum · malbum · CWE-264 | Critical10.0 | — | 3.6% | Feb 21, 2007 |
20Monitor | CVE-2006-6069No exploit | index.php in mAlbum 0.3 and earlier allows remote attackers to obtain the installation path via an invalid gal parameter.malbum · malbum | Medium5.0 | — | 1.2% | Nov 21, 2006 |
10Monitor | CVE-2006-6068No exploit | Directory traversal vulnerability in the cached_album function in functions.php for mAlbum 0.3 and earlier allows remote attackers to list fmalbum · malbum | Low2.6 | — | 1.4% | Nov 21, 2006 |
- CVE-2007-104541Plan
mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to g
CriticalCVSS 10.0No exploitEPSS 4%malbum · malbumFeb 21, 2007
- CVE-2006-606920Monitor
index.php in mAlbum 0.3 and earlier allows remote attackers to obtain the installation path via an invalid gal parameter.
MediumCVSS 5.0No exploitEPSS 1%malbum · malbumNov 21, 2006
- CVE-2006-606810Monitor
Directory traversal vulnerability in the cached_album function in functions.php for mAlbum 0.3 and earlier allows remote attackers to list f
LowCVSS 2.6No exploitEPSS 1%malbum · malbumNov 21, 2006