Vulnerabilities > Ampache > High

DATE CVE VULNERABILITY TITLE RISK
2023-02-10 CVE-2023-0771 SQL Injection vulnerability in Ampache
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
network
low complexity
ampache CWE-89
8.8
2021-04-13 CVE-2021-21399 Improper Authentication vulnerability in Ampache
Ampache is a web based audio/video streaming application and file manager.
network
low complexity
ampache CWE-287
7.5
2008-09-04 CVE-2008-3929 Link Following vulnerability in Ampache 3.4.1
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.
local
low complexity
ampache CWE-59
7.2
2006-11-03 CVE-2006-5668 Information Disclosure vulnerability in Ampache Guest Account
Unspecified vulnerability in Ampache 3.3.2 and earlier, when register_globals is enabled, allows remote attackers to bypass security restrictions and gain guest access.
network
low complexity
ampache
7.5