VYPR

Image Gallery

by Elkagroup

CVEs (4)

  • CVE-2009-4569Jan 5, 2010
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.

  • CVE-2009-1446Apr 27, 2009
    risk 0.03cvss epss 0.03

    Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5037Nov 12, 2008
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2007-3461Jun 27, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.