Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2012-4919 Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability Gallery No fix yet Fix from $2,3002020-01-22 MEDIUM 5.0 CVE-2006-4030 Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecifie… Gallery after 1.5.1_rc2 Fix from $1,6002006-08-16 MEDIUM 5.0 CVE-2006-1219 Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".."… Gallery Patch available Fix from $1,6002006-03-14 MEDIUM 6.4 CVE-2006-1126 Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checke… Gallery Patch available Fix from $1,6002006-03-09 MEDIUM 6.4 CVE-2006-1128 Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and… Gallery Patch available Fix from $1,6002006-03-09 MEDIUM 6.5 CVE-2006-0587 Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album d… Gallery Patch available Fix from $1,6002006-02-08 MEDIUM 5.0 CVE-2005-4021 The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote a… Gallery Mitigation only Fix from $1,6002005-12-05 MEDIUM 5.0 CVE-2005-4023 Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors. Gallery Patch available Fix from $1,6002005-12-05 MEDIUM 6.4 CVE-2005-3251 Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequ… Gallery Patch available Fix from $1,6002005-10-17 MEDIUM 5.0 CVE-2005-0220 Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username … Gallery Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0222 main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the … Gallery Mitigation only Fix from $1,6002005-05-02 HIGH 7.5 CVE-2004-1466EPSS 5% The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploade… Gallery Patch available Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-2124EPSS 7% The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a… Gallery Patch available Fix from $1,6002004-12-31 HIGH 7.5 CVE-2003-1227EPSS 7% PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remo… Gallery Patch available Fix from $1,9502003-12-31 HIGH 7.5 CVE-2002-1412EPSS 39% Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable… Gallery after 1.3.1 Fix from $1,9502003-04-11 HIGH 7.5 CVE-2002-2123 PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a… Gallery Patch available Fix from $1,9502002-12-31 HIGH 7.5 CVE-2002-2130 publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a … Gallery Patch available Fix from $1,9502002-12-31 HIGH 7.5 CVE-2001-1234 Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HT… Gallery Patch available Fix from $1,9502001-10-02