Vulnerabilities > Imgallery > Imgallery > 2.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-05-19 | CVE-2008-2337 | SQL Injection vulnerability in Imgallery 2.5 Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kategoria parameter to (a) galeria.php and the (2) id_phot parameter to (b) popup/koment.php and (c) popup/opis.php in, different vectors than CVE-2006-3163. | 7.5 |
2007-01-05 | CVE-2007-0082 | Unspecified vulnerability in Imgallery 2.4/2.5 users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts. | 6.5 |