Skip to content
Noroxi

phpwebgallery records

13 published records for vendor phpwebgallery.

All records

13 records
  • CVE-2008-4645
    38Monitor

    plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP c

    CriticalCVSS 9.0Proof of conceptEPSS 7%

    phpwebgallery · phpwebgalleryOct 21, 2008

  • CVE-2005-4228
    31Monitor

    Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (

    HighCVSS 7.5Proof of conceptEPSS 3%

    phpwebgallery · phpwebgalleryDec 14, 2005

  • CVE-2008-4702
    31Monitor

    Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpwebgallery · phpwebgalleryOct 22, 2008

  • CVE-2002-2064
    30Monitor

    isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.

    HighCVSS 7.5No exploitEPSS 2%

    phpwebgallery · phpwebgalleryDec 31, 2002

  • CVE-2006-1600
    30Monitor

    SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search

    HighCVSS 7.5No exploitEPSS 1%

    phpwebgallery · phpwebgalleryApr 3, 2006

  • CVE-2006-2041
    20Monitor

    PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat p

    MediumCVSS 5.0No exploitEPSS 1%

    phpwebgallery · phpwebgalleryApr 26, 2006

  • CVE-2007-1109
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3No exploitEPSS 2%

    phpwebgallery · phpwebgalleryFeb 26, 2007

  • CVE-2006-3476
    18Monitor

    Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to

    MediumCVSS 4.3Proof of conceptEPSS 2%

    phpwebgallery · phpwebgalleryJul 10, 2006

  • CVE-2008-4591
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject

    MediumCVSS 4.3Proof of conceptEPSS 2%

    phpwebgallery · phpwebgalleryOct 16, 2008

  • CVE-2007-5012
    17Monitor

    Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to

    MediumCVSS 4.3No exploitEPSS 1%

    phpwebgallery · phpwebgallerySep 20, 2007

  • CVE-2008-3451
    16Monitor

    PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users b

    MediumCVSS 4.0No exploitEPSS 1%

    phpwebgallery · phpwebgalleryAug 4, 2008

  • CVE-2006-1675
    11Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via

    LowCVSS 2.6Proof of conceptEPSS 2%

    phpwebgallery · phpwebgalleryApr 10, 2006

  • CVE-2006-1674
    10Monitor

    Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML

    LowCVSS 2.6No exploitEPSS 1%

    phpwebgallery · phpwebgalleryApr 10, 2006