Vulnerabilities > 4Images

DATE CVE VULNERABILITY TITLE RISK
2006-05-05 CVE-2006-2214 SQL Injection vulnerability in 4Images Image Gallery Management System 1.7.1
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php.
network
low complexity
4images
7.5
2006-02-27 CVE-2006-0899 Remote File Include vulnerability in 4images
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.
network
low complexity
4images
7.5