VYPR

Mcgallery

by Mcgallery

CVEs (3)

  • CVE-2007-1478Mar 16, 2007
    risk 0.03cvss epss 0.06

    download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.

  • CVE-2005-1998Jun 15, 2005
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

  • CVE-2005-1997Jun 15, 2005
    risk 0.00cvss epss 0.00

    show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.