Skip to main content

Vendor/product archive

gallery_project / gallery CVEs

Beta · best-effort

29 CVEs tagged to gallery_project / gallery2 Critical, 6 High, 21 Medium, 0 Low, 0 Unrated.

CVE-2006-4030

Published Aug 16, 2006

Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1696

Published Apr 11, 2006

Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1219

Published Mar 14, 2006

Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the st…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1126

Published Mar 9, 2006

Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1127

Published Mar 9, 2006

Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP hea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1128

Published Mar 9, 2006

Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying th…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0587

Published Feb 8, 2006

Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arb…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0330

Published Jan 21, 2006

Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4021

Published Dec 5, 2005

The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4022

Published Dec 5, 2005

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4023

Published Dec 5, 2005

Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3251

Published Oct 17, 2005

Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId paramet…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2734

Published Aug 30, 2005

Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Ta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2596

Published Aug 17, 2005

User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0219

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0220

Published May 2, 2005

Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0222

Published May 2, 2005

main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0221

Published Jan 17, 2005

Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1106

Published Jan 10, 2005

Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1466

Published Dec 31, 2004

The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2124

Published Dec 31, 2004

The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion att…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1227

Published Dec 31, 2003

PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0614

Published Aug 27, 2003

Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2