Vulnerabilities > Malbum

DATE CVE VULNERABILITY TITLE RISK
2007-02-21 CVE-2007-1045 Permissions, Privileges, and Access Controls vulnerability in Malbum 0.3
mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.
network
low complexity
malbum CWE-264
critical
10.0
2006-11-22 CVE-2006-6069 Remote Security vulnerability in mAlbum
index.php in mAlbum 0.3 and earlier allows remote attackers to obtain the installation path via an invalid gal parameter.
network
low complexity
malbum
5.0
2006-11-22 CVE-2006-6068 Directory Traversal vulnerability in mAlbum
Directory traversal vulnerability in the cached_album function in functions.php for mAlbum 0.3 and earlier allows remote attackers to list filenames of arbitrary images via a ..
network
high complexity
malbum
2.6