VYPR

Zenphoto

by Zenphoto

Source repositories

CVEs (33)

  • CVE-2015-5592Dec 31, 2019
    risk 0.00cvss epss 0.01

    Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.

  • CVE-2018-20140Mar 17, 2019
    risk 0.00cvss epss 0.02

    Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.

  • CVE-2015-2949May 31, 2015
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-2948May 31, 2015
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-7242Dec 31, 2013
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.

  • CVE-2013-7241Dec 31, 2013
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.

  • CVE-2012-2641Jul 5, 2012
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.

  • CVE-2012-0995Feb 21, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH_INFO…

  • CVE-2012-0994Feb 21, 2012
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.

  • CVE-2012-0993Feb 21, 2012
    risk 0.00cvss epss 0.03

    Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arbitrary PHP code via the viewer_size_image_saved cookie.

  • CVE-2008-6925Aug 10, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2007-0616Jan 31, 2007
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via ".." sequences in the album parameter to index.php.

  • CVE-2006-2186May 4, 2006
    risk 0.00cvss epss 0.02

    zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (2) /photos/themes/testing/ URIs, which reveals the path in an error message.

Page 2 of 2