VYPR

Photoalbum B&W

by Photoalbum B&W

CVEs (2)

  • CVE-2006-2729Jun 1, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2000-0902Dec 19, 2000
    risk 0.00cvss epss 0.01

    getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.