Skip to content
Noroxi

mcgallery records

7 published records for vendor mcgallery.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    7 records
    • CVE-2006-4720
      31Monitor

      PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL

      HighCVSS 7.5Proof of conceptEPSS 4%

      mcgallery · mcgallery proSep 12, 2006

    • CVE-2005-4251
      30Monitor

      Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1)

      HighCVSS 7.5Proof of conceptEPSS 1%

      mcgallery · mcgallery proDec 14, 2005

    • CVE-2005-4250
      21Monitor

      Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language paramete

      MediumCVSS 5.0Proof of conceptEPSS 3%

      mcgallery · mcgallery proDec 14, 2005

    • CVE-2005-1998
      21Monitor

      Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a ..

      MediumCVSS 5.0Proof of conceptEPSS 3%

      mcgallery · mcgalleryJun 15, 2005

    • CVE-2007-1478
      21Monitor

      download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.

      MediumCVSS 5.0Proof of conceptEPSS 2%

      mcgallery · mcgalleryMar 16, 2007

    • CVE-2005-1997
      20Monitor

      show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, v

      MediumCVSS 5.0No exploitEPSS 1%

      mcgallery · mcgalleryJun 15, 2005

    • CVE-2005-4252
      17Monitor

      Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via

      MediumCVSS 4.3No exploitEPSS 1%

      mcgallery · mcgallery proDec 14, 2005