Search CVE reports


Toggle filters

41 – 49 of 49 results


CVE-2007-6687

Low priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1) Core or (2) add-item modules; or via (3) HTTP...

2 affected packages

gallery, gallery2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery
gallery2
Show less packages

CVE-2007-6686

Medium priority
Ignored

The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.

2 affected packages

gallery, gallery2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery
gallery2
Show less packages

CVE-2007-6685

Low priority
Ignored

Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.

2 affected packages

gallery, gallery2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery
gallery2
Show less packages

CVE-2007-4650

Unknown priority
Ignored

Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit...

1 affected package

gallery2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery2
Show less packages

CVE-2007-3154

Low priority
Not affected

Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.

3 affected packages

dtc-common, egroupware, gallery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dtc-common
egroupware
gallery
Show less packages

CVE-2006-1219

Unknown priority
Fixed

Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2)...

1 affected package

gallery2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery2
Show less packages

CVE-2005-2596

Unknown priority
Fixed

User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.

1 affected package

gallery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery
Show less packages

CVE-2005-0220

Unknown priority
Fixed

Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.

1 affected package

gallery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery
Show less packages

CVE-2005-0219

Unknown priority
Fixed

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full,...

1 affected package

gallery

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gallery
Show less packages