mcgallery records
7 published records for vendor mcgallery.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-4720Proof of concept | PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL mcgallery · mcgallery pro | High7.5 | — | 3.5% | Sep 12, 2006 |
30Monitor | CVE-2005-4251Proof of concept | Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1)mcgallery · mcgallery pro | High7.5 | — | 1.3% | Dec 14, 2005 |
21Monitor | CVE-2005-4250Proof of concept | Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parametemcgallery · mcgallery pro | Medium5.0 | — | 3.1% | Dec 14, 2005 |
21Monitor | CVE-2005-1998Proof of concept | Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a ..mcgallery · mcgallery | Medium5.0 | — | 3.1% | Jun 15, 2005 |
21Monitor | CVE-2007-1478Proof of concept | download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.mcgallery · mcgallery · CWE-20 | Medium5.0 | — | 2.5% | Mar 16, 2007 |
20Monitor | CVE-2005-1997No exploit | show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, vmcgallery · mcgallery | Medium5.0 | — | 1.4% | Jun 15, 2005 |
17Monitor | CVE-2005-4252No exploit | Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML viamcgallery · mcgallery pro | Medium4.3 | — | 1.2% | Dec 14, 2005 |
- CVE-2006-472031Monitor
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL
HighCVSS 7.5Proof of conceptEPSS 4%mcgallery · mcgallery proSep 12, 2006
- CVE-2005-425130Monitor
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1)
HighCVSS 7.5Proof of conceptEPSS 1%mcgallery · mcgallery proDec 14, 2005
- CVE-2005-425021Monitor
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language paramete
MediumCVSS 5.0Proof of conceptEPSS 3%mcgallery · mcgallery proDec 14, 2005
- CVE-2005-199821Monitor
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 3%mcgallery · mcgalleryJun 15, 2005
- CVE-2007-147821Monitor
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.
MediumCVSS 5.0Proof of conceptEPSS 2%mcgallery · mcgalleryMar 16, 2007
- CVE-2005-199720Monitor
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, v
MediumCVSS 5.0No exploitEPSS 1%mcgallery · mcgalleryJun 15, 2005
- CVE-2005-425217Monitor
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 1%mcgallery · mcgallery proDec 14, 2005