Vulnerabilities > Ktools

DATE CVE VULNERABILITY TITLE RISK
2017-04-12 CVE-2016-4337 SQL Injection vulnerability in Ktools Photostore 4.7.4
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.
network
low complexity
ktools CWE-89
7.5
2009-04-07 CVE-2008-6649 SQL Injection vulnerability in Ktools Photostore
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
ktools CWE-89
7.5
2009-04-07 CVE-2008-6648 SQL Injection vulnerability in Ktools Photostore 3.4.3/3.5.2
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php.
network
low complexity
ktools CWE-89
7.5
2009-04-07 CVE-2008-6647 SQL Injection vulnerability in Ktools Photostore 3.4.3
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter.
network
low complexity
ktools CWE-89
7.5
2005-11-29 CVE-2005-3863 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ktools
Stack-based buffer overflow in kkstrtext.h in ktools library 0.3 and earlier, as used in products such as (1) centericq, (2) orpheus, (3) motor, and (4) groan, allows local users or remote attackers to execute arbitrary code via a long parameter to the VGETSTRING macro.
network
low complexity
ktools CWE-119
7.5