VYPR

Ampache

by Ampache

Source repositories

CVEs (26)

  • CVE-2023-0606MedFeb 1, 2023
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.

  • CVE-2022-4665HigDec 23, 2022
    risk 0.00cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

  • CVE-2008-3929Sep 4, 2008
    risk 0.00cvss —epss 0.00

    gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

  • CVE-2007-4437Aug 20, 2007
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. NOTE: some details are obtained from third party information.

  • CVE-2007-4438Aug 20, 2007
    risk 0.00cvss —epss 0.01

    Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

  • CVE-2006-5668Nov 3, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and gain guest access.

Page 2 of 2