Unrated severityNVD Advisory· Published Feb 21, 2012· Updated Apr 29, 2026
CVE-2012-0993
CVE-2012-0993
Description
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arbitrary PHP code via the viewer_size_image_saved cookie.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- archives.neohapsis.com/archives/bugtraq/2012-02/0037.htmlnvdExploit
- www.securityfocus.com/bid/51916nvdExploit
- www.zenphoto.org/trac/changeset/8994nvdExploitPatch
- www.zenphoto.org/trac/changeset/8995nvdExploitPatch
- www.htbridge.ch/advisory/HTB23070nvdExploit
- secunia.com/advisories/47875nvdVendor Advisory
- www.zenphoto.org/news/zenphoto-1.4.2.1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/73081nvd
News mentions
0No linked articles in our index yet.