CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2008-4702 HIGH

Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in t…

CVSS 7.5 EPSS 2.49% Oct 22, 2008
CVE-2008-4645 HIGH

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequenc…

CVSS 9.0 EPSS 7.12% Oct 21, 2008
CVE-2008-4591 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web scri…

CVSS 4.3 EPSS 1.51% Oct 16, 2008
CVE-2008-3451 MEDIUM

PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user'…

CVSS 4.0 EPSS 1.15% Aug 4, 2008
CVE-2007-5012 MEDIUM

Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to inject arbitrary w…

CVSS 4.3 EPSS 1.03% Sep 20, 2007
CVE-2007-1109 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) login or (…

CVSS 4.3 EPSS 1.98% Feb 26, 2007
CVE-2006-3476 MEDIUM

Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary we…

CVSS 4.3 EPSS 1.94% Jul 10, 2006
CVE-2006-2041 MEDIUM

PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the…

CVSS 5.0 EPSS 1.38% Apr 26, 2006
CVE-2006-1675 LOW

Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) n…

CVSS 2.6 EPSS 1.90% Apr 10, 2006
CVE-2006-1674 LOW

Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id paramet…

CVSS 2.6 EPSS 0.91% Apr 10, 2006
CVE-2006-1600 HIGH

SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

CVSS 7.5 EPSS 1.11% Apr 3, 2006
CVE-2005-4228 HIGH

Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_…

CVSS 7.5 EPSS 2.56% Dec 14, 2005
CVE-2002-2064 HIGH

isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.

CVSS 7.5 EPSS 1.53% Jul 14, 2005

Showing 1 to 13 CVEs · page 1