Skip to content
Noroxi

malbum records

3 published records for vendor malbum.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    3 records
    • mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to g

      CriticalCVSS 10.0No exploitEPSS 4%

      malbum · malbumFeb 21, 2007

    • CVE-2006-6069
      20Monitor

      index.php in mAlbum 0.3 and earlier allows remote attackers to obtain the installation path via an invalid gal parameter.

      MediumCVSS 5.0No exploitEPSS 1%

      malbum · malbumNov 21, 2006

    • CVE-2006-6068
      10Monitor

      Directory traversal vulnerability in the cached_album function in functions.php for mAlbum 0.3 and earlier allows remote attackers to list f

      LowCVSS 2.6No exploitEPSS 1%

      malbum · malbumNov 21, 2006