phpwebgallery kayıtları
phpwebgallery üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2008-4645Kavram kanıtı | plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP cphpwebgallery · phpwebgallery · CWE-94 | Kritik9,0 | — | %7,1 | 21 Eki 2008 |
31İzleyin | CVE-2005-4228Kavram kanıtı | Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (phpwebgallery · phpwebgallery · CWE-89 | Yüksek7,5 | — | %2,6 | 14 Ara 2005 |
31İzleyin | CVE-2008-4702Kavram kanıtı | Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via phpwebgallery · phpwebgallery · CWE-22 | Yüksek7,5 | — | %2,5 | 22 Eki 2008 |
30İzleyin | CVE-2002-2064İstismar yok | isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.phpwebgallery · phpwebgallery | Yüksek7,5 | — | %1,5 | 31 Ara 2002 |
30İzleyin | CVE-2006-1600İstismar yok | SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search phpwebgallery · phpwebgallery | Yüksek7,5 | — | %1,1 | 3 Nis 2006 |
20İzleyin | CVE-2006-2041İstismar yok | PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat pphpwebgallery · phpwebgallery | Orta5,0 | — | %1,4 | 26 Nis 2006 |
18İzleyin | CVE-2007-1109İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML viaphpwebgallery · phpwebgallery · CWE-79 | Orta4,3 | — | %2,0 | 26 Şub 2007 |
18İzleyin | CVE-2006-3476Kavram kanıtı | Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to phpwebgallery · phpwebgallery | Orta4,3 | — | %1,9 | 10 Tem 2006 |
17İzleyin | CVE-2008-4591Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to injectphpwebgallery · phpwebgallery · CWE-79 | Orta4,3 | — | %1,5 | 16 Eki 2008 |
17İzleyin | CVE-2007-5012İstismar yok | Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers tophpwebgallery · phpwebgallery · CWE-79 | Orta4,3 | — | %1,0 | 20 Eyl 2007 |
16İzleyin | CVE-2008-3451İstismar yok | PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users bphpwebgallery · phpwebgallery · CWE-200 | Orta4,0 | — | %1,2 | 4 Ağu 2008 |
11İzleyin | CVE-2006-1675Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML viaphpwebgallery · phpwebgallery | Düşük2,6 | — | %1,9 | 10 Nis 2006 |
10İzleyin | CVE-2006-1674İstismar yok | Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTMLphpwebgallery · phpwebgallery | Düşük2,6 | — | %0,9 | 10 Nis 2006 |
- CVE-2008-464538İzleyin
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP c
KritikCVSS 9,0Kavram kanıtıEPSS %7phpwebgallery · phpwebgallery21 Eki 2008
- CVE-2005-422831İzleyin
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpwebgallery · phpwebgallery14 Ara 2005
- CVE-2008-470231İzleyin
Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpwebgallery · phpwebgallery22 Eki 2008
- CVE-2002-206430İzleyin
isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.
YüksekCVSS 7,5İstismar yokEPSS %2phpwebgallery · phpwebgallery31 Ara 2002
- CVE-2006-160030İzleyin
SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search
YüksekCVSS 7,5İstismar yokEPSS %1phpwebgallery · phpwebgallery3 Nis 2006
- CVE-2006-204120İzleyin
PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat p
OrtaCVSS 5,0İstismar yokEPSS %1phpwebgallery · phpwebgallery26 Nis 2006
- CVE-2007-110918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3İstismar yokEPSS %2phpwebgallery · phpwebgallery26 Şub 2007
- CVE-2006-347618İzleyin
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to
OrtaCVSS 4,3Kavram kanıtıEPSS %2phpwebgallery · phpwebgallery10 Tem 2006
- CVE-2008-459117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject
OrtaCVSS 4,3Kavram kanıtıEPSS %2phpwebgallery · phpwebgallery16 Eki 2008
- CVE-2007-501217İzleyin
Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to
OrtaCVSS 4,3İstismar yokEPSS %1phpwebgallery · phpwebgallery20 Eyl 2007
- CVE-2008-345116İzleyin
PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users b
OrtaCVSS 4,0İstismar yokEPSS %1phpwebgallery · phpwebgallery4 Ağu 2008
- CVE-2006-167511İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via
DüşükCVSS 2,6Kavram kanıtıEPSS %2phpwebgallery · phpwebgallery10 Nis 2006
- CVE-2006-167410İzleyin
Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML
DüşükCVSS 2,6İstismar yokEPSS %1phpwebgallery · phpwebgallery10 Nis 2006