Page 7 of 78 results (0.006 seconds)

CVSS: 7.5EPSS: 0%CPEs: 9EXPL: 0

05 Dec 2005 — Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors. • http://secunia.com/advisories/17747 •

CVSS: 7.5EPSS: 1%CPEs: 8EXPL: 1

17 Oct 2005 — Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter. • http://dipper.info/security/20051012 •

CVSS: 6.1EPSS: 0%CPEs: 14EXPL: 0

29 Aug 2005 — Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285 •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

17 Aug 2005 — User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries. • http://gallery.menalto.com/index.php?name=PNphpBB2&file=viewtopic&t=7048 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2005 — Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php. • http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2005 — Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field. • http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2005 — main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message. • http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 3

17 Jan 2005 — Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field. • http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html •

CVSS: 9.8EPSS: 10%CPEs: 1EXPL: 3

31 Dec 2004 — The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root. • https://www.exploit-db.com/exploits/24383 •

CVSS: 9.1EPSS: 6%CPEs: 5EXPL: 1

31 Dec 2004 — The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. • https://www.exploit-db.com/exploits/23599 •