Skip to main content

Vendor archive

gallarific CVEs

Beta · best-effort

6 CVEs tagged to vendor gallarific0 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2011-0519

Published Jan 20, 2011

SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6567

Published Mar 31, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free Edition allow remote attackers to inject arbitrary web script or HTML via (1) the e-mail address, (2) a comm…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1464

Published Mar 24, 2008

Multiple SQL injection vulnerabilities in Gallarific Free Edition 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) query parameter to (a) search.php; (2) g…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1469

Published Mar 24, 2008

Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1326

Published Mar 13, 2008

Cross-site scripting (XSS) vulnerability in search.php in Gallarific allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1327

Published Mar 13, 2008

Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1