VYPR

Video Gallery Module

by PHP-Nuke

CVEs (3)

  • CVE-2004-1972Apr 26, 2004
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.

  • CVE-2008-4804Oct 31, 2008
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parameter in a showalbum action to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue was…

  • CVE-2004-1971Apr 26, 2004
    risk 0.00cvss epss 0.01

    modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message.