VYPR

Photoalbum B&W

by Photoalbum B&W

CVEs (4)

  • CVE-2009-4819Apr 27, 2010
    risk 0.03cvss epss 0.03

    Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/.

  • CVE-2008-2501May 29, 2008
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayimage.php.

  • CVE-2006-2729Jun 1, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2000-0902Dec 19, 2000
    risk 0.00cvss epss 0.01

    getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.