VYPR

Tftgallery

by Tftgallery

CVEs (3)

  • CVE-2009-3912Nov 9, 2009
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.

  • CVE-2009-3911Nov 9, 2009
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sample parameter.

  • CVE-2009-3833Nov 2, 2009
    risk 0.03cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album parameter.